The @lottiefiles/lottie-player npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 30 Oct 2024 · npm
@lottiefiles/lottie-player 2.0.4 -> 2.0.5, 2.0.6, 2.0.7the built dist bundleOn 30 October 2024, attackers published three bad versions of the npm package @lottiefiles/lottie-player: 2.0.5, 2.0.6 and 2.0.7. The code showed a "Connect Wallet" prompt to site visitors. Version 2.0.4 and earlier, and version 2.0.8 and later, are safe.
Cycode reports about 100,000 weekly downloads for the package. Sites that loaded it from a CDN with the latest tag served the bad code to their visitors.
What happened
An attacker published three malicious releases straight to npm, with no GitHub release or code review. LottieFiles states that the attacker took over an employee's npm account by phishing. Snyk and Cycode describe a stolen or exposed npm token. Both descriptions fit the same result: the attacker can publish directly.
Cycode lists the publish times on 30 October 2024 as 20:12 GMT (2.0.5), 20:35 GMT (2.0.6) and 21:57 GMT (2.0.7). Someone opened a public issue about the bad versions about four hours after the first one.
The added code showed a cryptocurrency wallet connection menu. Snyk names MetaMask, WalletConnect and Phantom as the options. Cycode adds that the code included Ethereum functions to run transactions and web3 requests. LottieFiles calls it a Bitcoin drainer. The goal was to take funds from visitors who connected a wallet.
Two groups were exposed. Developers who installed a bad version through npm during the window, and visitors to sites that loaded the package from unpkg, jsDelivr or a similar CDN with the latest tag. LottieFiles states that no customer data, infrastructure or other services were compromised.
Vigilance compares the version you trust with the new one. These three versions changed the package files in a way that added wallet code. Vigilance reports the file that gained a new capability. See the scan block below.
Affected versions
@lottiefiles/lottie-player2.0.5, 2.0.6 and 2.0.7. npm removed them.- Safe: 2.0.4 and earlier, and 2.0.8 and later (Snyk).
Indicators of compromise
- Package name and versions above in a lockfile, an npm cache or a CDN URL.
- A "Connect Wallet" menu on a page that only plays Lottie animations.
- CDN links to
unpkg.comorcdn.jsdelivr.netfor@lottiefiles/lottie-playerthat use@latestor no version. - Snyk vulnerability ID
SNYK-JS-LOTTIEFILESLOTTIEPLAYER-8310516.
The sources list no wallet-drainer domains or file hashes, so this page lists none.
How to check
Find the installed version in each project.
npm ls @lottiefiles/lottie-player
Then search your source and templates for unpinned CDN links.
grep -rn "lottie-player" --include=*.html --include=*.js --include=*.json . | grep -v node_modules
Any 2.0.5, 2.0.6 or 2.0.7 in a lockfile means a bad version was installed. A CDN link with no version number possibly served it on 30 and 31 October 2024.
What to do now
- Upgrade to 2.0.8 or later, or go back to 2.0.4. Clear the npm cache and rebuild.
- Pin the version in every CDN link. Do not use
@latestin production. - Add a Content Security Policy that limits where scripts can load from.
- If your site served a bad version, tell your users who connected a wallet during the window. They must check their wallets.
- Publishers: protect npm accounts with strong two-factor sign-in and use npm provenance.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 66 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED package.json It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which versions of @lottiefiles/lottie-player were compromised?
Versions 2.0.5, 2.0.6 and 2.0.7 were malicious. Version 2.0.8 is the clean fix, and 2.0.4 and earlier are safe.
What did the malicious lottie-player code do?
It showed a Connect Wallet menu with options such as MetaMask, WalletConnect and Phantom. The aim was to drain funds from visitors who connected a wallet.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.