Massive Supply Chain attack
AI summary of the linked articleA supply chain attack on the popular JavaScript library lottie-player injected code that displayed a Web3 wallet connection pop-up on legitimate websites. The author's timeline says a user reported the issue on GitHub about three hours before the post, and that the attack appeared to target major crypto websites that use the library. The post links the compromise to a maintainer account whose tokens were reportedly compromised, allowing malicious code to be published in versions 2.0.5, 2.0.6 and 2.0.7 on npm, pushed on 30 October 2024. According to the post, the affected versions have been removed from npm and most major CDNs, but sites that directly reference them remain vulnerable and should move to 2.0.4 or update to 2.0.8. | |
Recommended by 1 curator | |
Characters remaining: 10,000 comment guidelines | |
More from x.com on Kiwi News
| |
