The @lottiefiles/lottie-player npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 30 Oct 2024 · npm

Package@lottiefiles/lottie-player 2.0.4 -> 2.0.5, 2.0.6, 2.0.7
Filethe built dist bundle

On 30 October 2024, attackers published three bad versions of the npm package @lottiefiles/lottie-player: 2.0.5, 2.0.6 and 2.0.7. The code showed a "Connect Wallet" prompt to site visitors. Version 2.0.4 and earlier, and version 2.0.8 and later, are safe.

Cycode reports about 100,000 weekly downloads for the package. Sites that loaded it from a CDN with the latest tag served the bad code to their visitors.

What happened

An attacker published three malicious releases straight to npm, with no GitHub release or code review. LottieFiles states that the attacker took over an employee's npm account by phishing. Snyk and Cycode describe a stolen or exposed npm token. Both descriptions fit the same result: the attacker can publish directly.

Cycode lists the publish times on 30 October 2024 as 20:12 GMT (2.0.5), 20:35 GMT (2.0.6) and 21:57 GMT (2.0.7). Someone opened a public issue about the bad versions about four hours after the first one.

The added code showed a cryptocurrency wallet connection menu. Snyk names MetaMask, WalletConnect and Phantom as the options. Cycode adds that the code included Ethereum functions to run transactions and web3 requests. LottieFiles calls it a Bitcoin drainer. The goal was to take funds from visitors who connected a wallet.

Two groups were exposed. Developers who installed a bad version through npm during the window, and visitors to sites that loaded the package from unpkg, jsDelivr or a similar CDN with the latest tag. LottieFiles states that no customer data, infrastructure or other services were compromised.

Vigilance compares the version you trust with the new one. These three versions changed the package files in a way that added wallet code. Vigilance reports the file that gained a new capability. See the scan block below.

Affected versions

Indicators of compromise

The sources list no wallet-drainer domains or file hashes, so this page lists none.

How to check

Find the installed version in each project.

npm ls @lottiefiles/lottie-player

Then search your source and templates for unpinned CDN links.

grep -rn "lottie-player" --include=*.html --include=*.js --include=*.json . | grep -v node_modules

Any 2.0.5, 2.0.6 or 2.0.7 in a lockfile means a bad version was installed. A CDN link with no version number possibly served it on 30 and 31 October 2024.

What to do now

  1. Upgrade to 2.0.8 or later, or go back to 2.0.4. Clear the npm cache and rebuild.
  2. Pin the version in every CDN link. Do not use @latest in production.
  3. Add a Content Security Policy that limits where scripts can load from.
  4. If your site served a bad version, tell your users who connected a wallet during the window. They must check their wallets.
  5. Publishers: protect npm accounts with strong two-factor sign-in and use npm provenance.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old @lottiefiles/lottie-player-2.0.4 --new @lottiefiles/lottie-player-2.0.5
files scanned: 66

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.json
           It now downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which versions of @lottiefiles/lottie-player were compromised?

Versions 2.0.5, 2.0.6 and 2.0.7 were malicious. Version 2.0.8 is the clean fix, and 2.0.4 and earlier are safe.

What did the malicious lottie-player code do?

It showed a Connect Wallet menu with options such as MetaMask, WalletConnect and Phantom. The aim was to drain funds from visitors who connected a wallet.

Sources

  1. snyk.io/blog/lottie-player-npm-package-compromised-crypto-wallet-theft/
  2. cycode.com/blog/lottie-web-player-malicious-package/
  3. lottiefiles.com/blog/inside-lottiefiles/resolution-of-security-incident-with-lottiefiles-lottie-player-package

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free