CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Supply chain attack on lottie-player: everything you need to know

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1536

As cited

Copy frozen at (site build).

breaches incidents

Supply chain attack on lottie-player: everything you need to know

A supply chain attack compromised the lottie-player library, a popular tool used in web development. The compromised versions inject malicious Web3 wallet prompts into affected websites. Users should update to a patched version or revert to an earlier uncompromised release.

Why it matters: Developers and web administrators using lottie-player need to audit and patch immediately to prevent their sites from displaying credential-harvesting prompts to users.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary