Incident tracker · 30 Oct 2024

Are you exposed to the @lottiefiles/lottie-player supply-chain (October 2024)?

Maintainer's npm credentials compromised; attackers published versions injecting a Web3 wallet-drainer into thousands of downstream sites.

Confirmed-compromised packages1 package
npm
@lottiefiles/lottie-playercompromised: 2.0.5, 2.0.6, 2.0.7
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo