What is Nostr?
zCat
npub1zm7…pnd6
2024-11-25 23:46:33

zCat on Nostr: npm Package Lottie-Player Compromised in Supply Chain Attack A targeted supply chain ...

npm Package Lottie-Player Compromised in Supply Chain Attack

A targeted supply chain attack involving the widely used npm package @lottiefiles/lottie-player has been uncovered, highlighting vulnerabilities in software dependencies.

The @lottiefiles/lottie-player package was downloaded approximately 84,000 times weekly and is used to embed and play Lottie animations on websites.

The malicious updates contained altered code that introduced pop-ups prompting users to connect their web3 wallets.

See more: https://www.infosecurity-magazine.com/news/npm-package-lottieplayer-supply/

#cybersecurity #malware #cryptocurrency
Author Public Key
npub1zm7jduqq2nmxz5wxh4ujtm00g9vxzqa0r82yt7flvm67yje5gfaqa5pnd6