Massive Supply Chain attack

@galnagli
@galnagli

TLDR: Massive Supply Chain attack had been happening on the highly popular JS Library lottie-player since ~2 hours ago that populates attackers Web3 wallet connection pop-up on legitimate websites. I'll write here what we know, what can be done and how to detect it in the wild. You can track the entire conversations and remediation through https://github.com/LottieFiles/lottie-pl… - just to give a timeline of events 3 Hours ago, lottie-player end-user created the linked issue ^ on GitHub, specifying that while seamlessly including the lottie-player library on his website, it populated a Web3 wallet connection: Simple inclusion of https://unpkg.com/@lottiefiles/lottie-pl… or https://cdn.jsdelivr.net/npm/@lottiefile… Led to: Users were experiencing the same on popular websites all across the internet, like @tryhackme and it seems that the original attack intent was to target major crypto websites who utilize the library. 1 Hour ago, VP of Engineering at Lottie was tackling the issue within the GitHub thread As some users who investigated already came to speculations, it seems that one of the maintainers accounts tokens - https://github.com/Aidosmf had been compromised and allowed attackers to plant malicious code on ~3 versions across NPM https://www.npmjs.com/package/@lottiefil… 2.0.5 - pushed to npm at 8:12 PM GMT, 30 Oct 2024 2.0.6 - pushed to npm at 8:35 PM GMT, 30 Oct 2024 2.0.7 - pushed to npm at 9:57 PM GMT, 30 Oct 2024 As of the latest update 20 minutes ago, seems that the original infected package was removed from NPM and most of leading CDNs, however websites who directly reference the affected versions are probably still vulnerable and need to either backport to 2.04 or update to 2.08 "The affected versions have now been removed from http://npmjs.com (2.0.5, 2.0.6, 2.0.7)." Another GitHub user has included a gist with reference to the malware itself https://gist.github.com/jkobus/57f7a198c… If you'd like to probe your web assets and see which one of them are using one of the still affected versions, you can use the following Nuclei Template: https://gist.github.com/NagliNagli/be5f4… I'll update the thread if anything new comes up.

Tweet image
x.com
by mishaderidder.eth13093 🥝 • 2y • x.com
AI summary of the linked article

A supply chain attack on the popular JavaScript library lottie-player injected code that displayed a Web3 wallet connection pop-up on legitimate websites. The author's timeline says a user reported the issue on GitHub about three hours before the post, and that the attack appeared to target major crypto websites that use the library. The post links the compromise to a maintainer account whose tokens were reportedly compromised, allowing malicious code to be published in versions 2.0.5, 2.0.6 and 2.0.7 on npm, pushed on 30 October 2024. According to the post, the affected versions have been removed from npm and most major CDNs, but sites that directly reference them remain vulnerable and should move to 2.0.4 or update to 2.0.8.

Recommended by 1 curator
This is great 👍
Characters remaining: 10,000

comment guidelines