Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
    • Layer 2
  • Tech
    • Blockchain
    • Security and Privacy
    • Mining
  • Web 3
    • Web3 News
    • DeFi
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
What's Hot

Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

15 June 2025

Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

15 June 2025

$1.14 Billion Wiped Out as Market Faces Double Attack? 

15 June 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) LinkedIn
The Coin VibeThe Coin Vibe
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. Layer 2
    6. View All

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    15 June 2025

    $190,000 Bitcoin Within the ‘Realm of Possibility,’ According to Analyst Kevin Svenson – Here’s His Outlook

    15 June 2025

    Sell-Off Continues as SHIB Burn Rate Skyrockets to 112,000%

    15 June 2025

    The 30,000-Foot View Of The Oslo Freedom Forum

    15 June 2025

    Solana or Ethereum? – The fight for Q3 dominance starts now!

    15 June 2025

    $298 mln Ethereum liquidated across 80K traders: Yet BlackRock keeps buying

    15 June 2025

    Ethereum whales boost holdings by 1.49 mln – Can this trigger ETH’s breakout?

    14 June 2025

    What’s making Ethereum more attractive than Bitcoin right now

    14 June 2025

    Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

    15 June 2025

    Solaxy Claim Guide and 2025’s Breakout Coin to watch: Pepeto

    15 June 2025

    Analysis of the 4-day drop of XRP: whale output; Is it time for the retail trade to board?

    15 June 2025

    Ethereum Weekly Candle Hints on pre-tower Top formation details

    15 June 2025

    Shiba Inu Burn Rate Spikes 3,484% as Kusama Teases AI Push

    14 June 2025

    Shiba Inu Enters AI-Gaming as SHIB Price Hits Critical Support

    13 June 2025

    The $CVB Launch Is Here — And It Starts With You

    13 June 2025

    Here’s What’s Pumping in June

    11 June 2025

    Soneium layer 2 launches gaming incubator to support projects and drive ecosystem adoption

    9 June 2025

    Immutable price drops even as Guild of Guardians NFT sales jump

    6 June 2025

    Cryptocurrencies to watch this week: Pi, Immutable, Zebec

    1 June 2025

    GOAT Network launches dashboard for first suite of on-chain Bitcoin yield products

    29 May 2025

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

    15 June 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    15 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. Mining
    4. View All

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    Quack AI Partners SoonChain to Redefine Governance in Web3 Gaming

    15 June 2025

    CESS Network Integrates with Blazpay to Redefine DePIN and AI Storage

    15 June 2025

    Nillion Network and Cloudician Launch Privacy-First Petnet Node

    15 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025

    Inferno Drainer Spoofs Over 100 Crypto Brands to Steal $80m+

    15 June 2025

    Crypto Heists Surge in 2023, $16.93m Already Stolen in 2024

    15 June 2025

    Phemedrone Stealer Targets Windows Defender Flaw Despite Patch

    15 June 2025

    Russian Police Bust Truck-Based Crypto Mine Stealing Village Power

    15 June 2025

    France eyes Bitcoin mining as means to manage energy

    15 June 2025

    946 Exahash—Miners Push Bitcoin to New Computational Heights Despite Pay Drop

    14 June 2025

    Bitcoin Miners Just Had One of Their Best Quarters on Record, JPMorgan Says

    14 June 2025

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

    15 June 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    15 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025
  • Web 3
    1. Web3 News
    2. DeFi
    3. View All

    XRP News: Vaultro Finance Presale on XRP ledger Skyrockets Past 50%, As Investors Race to Own $VLT Token

    15 June 2025

    Earn 5x GUN Tokens Monthly: A Complete Guide to Off the Grid Battle Pass

    15 June 2025

    United States Image Recognition Market Size & Industry Report 2033

    15 June 2025

    Off The Grid Set to Launch on Steam With Optional NFTs

    15 June 2025

    Sentora Highlights Capital Fragmentation and Infrastructure Gaps in Institutional DeFi

    15 June 2025

    MOCA Launches on Coinbase through Aerodrome DEX Integration, Expanding DeFi Access 

    15 June 2025

    SOL Rebounds Toward $145 as 7 ETFs Advance and DeFi Dev Corp Eyes More SOL Purchases

    14 June 2025

    Gold Enters DeFi With Launch of Tokenized Asset XAUT0

    14 June 2025

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

    15 June 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    15 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Elizabeth Warren, Consumer Groups Slam Walmart and Amazon Stablecoin Plans

    15 June 2025

    New and Important Development in the Ripple vs. SEC Lawsuit – All Eyes on the Judge Now

    15 June 2025

    Walmart, Amazon and Other Multinational Giants Considering Issuing Stablecoins: Report

    15 June 2025

    US prosecutors say Tornado Cash witnesses will ‘waste jury time’

    15 June 2025

    KuCoin EU Appoints Banking Veteran Christian Derler And Legal Expert Tamara Rubey

    10 June 2025

    GameStop Drives Strategic Diversification With Staggering 4,710 $BTC Buyout

    28 May 2025

    Bybit Receives Clearance From French Regulator, Eyes MiCA License For Compliance Boost

    22 May 2025

    Bitget Secures VASP License In Bulgaria, Strengthening EU Expansion

    22 May 2025

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

    15 June 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    15 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025
  • Analysis

    Crypto Strategist Warns of up to 80% Bitcoin Correction in Next Bear Market Fueled by Selling of Major BTC Adoption Group

    15 June 2025

    Bullish and Bearish Scenarios Explained

    15 June 2025

    Can Pi Network Price Hit $10?

    15 June 2025

    Billionaire Investor Ray Dalio Outlines Meme Stock Trading Strategy, Says Investors Are Not Paying Enough Attention to the ‘Most Important Thing’

    14 June 2025

    This Dogecoin Rival Could Go Higher Amid Increased Whale Activity, Says Analytics Platform Santiment

    13 June 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    The Crypto Minimalist: Building Wealth by Doing Less

    15 June 2025

    The Crypto-Side Hustle Blueprint: How to Earn in Web3 Without Trading

    13 June 2025

    What is LIBRA? The Solana Meme Coin That Sparked a Political Scandal

    12 June 2025

    Living on Crypto: A 30-Day Real-World Challenge (And What I Learned)

    12 June 2025

    Binance Is Not Dumping SOL And ETH Through Wintermute

    23 May 2025

    US SEC Agency Drops Gemini & Tron ($TRX) Lawsuit

    23 May 2025

    Nischal Says Voting On The Wazirx Restructuring Scheme Will Start On 19 March

    22 May 2025

    Coinbase Secures Regulatory Approval To Resume Services In India

    22 May 2025

    Sonic Supercharges Onchain Insights with Bubblemaps V2 Integration

    15 June 2025

    Weekly winners and losers of Crypto Market – AB, Aero, Dexe, Kas

    15 June 2025

    $1.14 Billion Wiped Out as Market Faces Double Attack? 

    15 June 2025

    Senators Demand Probe into SEC Hack After Bitcoin Price Spike

    15 June 2025
  • Tools
    • Market Overview
    • Exchange Tool
  • Shop
Subscribe
The Coin VibeThe Coin Vibe
Home»Security and Privacy»npm Package Lottie-Player Compromised in Supply Chain Attack
Security and Privacy

npm Package Lottie-Player Compromised in Supply Chain Attack

30 May 2025No Comments2 Mins Read
Share Facebook Twitter LinkedIn
npm Package Lottie-Player Compromised in Supply Chain Attack
Share
Facebook Twitter LinkedIn

A targeted Supply Chain attack involving the widely used NPM package @Lottiveiles/Lottie player is discovered, in which vulnerabilities are emphasized in software dependencies.

According to research that was published by Reversinglabs last week, malignant versions of the package were released earlier this year.

Most important details of the incident

The Package @LotteViles/Lottie-Player has been downloaded around 84,000 times a week and is used to locking up and play Lottie animations on websites.

Although usually safe, malignant actors recently endangered the package by publishing three malignant versions – 2.0.5, 2.0.6 and 2.0.7 – through unauthorized access to a privileged developer account.

These malignant updates contain changed code that introduced pop-ups that encourage users to connect their web3 portfolios.

At Connection, attackers were given access to remove the crypto wallet assets from victims. Developers marked the problem soon after noting of unusual behavior on affected sites, which brought discussions on forums and Github.

Fast response from administrators

Lottyiles immediately responded to the infringement and worked with NPM to remove the malignant versions and to publish a clean version based on the latest secure release – version 2.0.4. Developers who use the @latest dependence configuration that have received automatic updates, which sent potential effects.

Read more about the security of the Supply Chain: CISA insists on improvements in the transparency of the American software -supply chain

How the compromise was detected

Reversinglabs researchers performed a differential analysis between Secure 2.0.4 and the Malicious 2.0.7 versions. This unveiled significant changes, including:

  • Increased file size without functional justification

  • Introduction of URL’s associated with Bitcoin exchanges

  • Removal of standard behavior, such as display list

See also  Ebury Botnet Operators Diversify with Financial and Crypto Theft

Their analysis also marked threat-hunting policy that detected patterns comparable to known attacks by Software-Supply Chain, such as crypto-token detection.

Lessons for developers

The attack underlines the importance of securing dependencies on specific, extended versions to prevent vulnerabilities in automatically updated packages. Regular security assessments of dependencies and construction pipelines are also crucial to identify potential risks.

“In the case of the @LotteViles/Lottie player, the Supply Chain compromise was quickly discovered. That does not mean that malicious actors could not work in the future to be even more secret and better in hiding their malignant code,” warned reversing labs.

“That is why it is necessary for developers to perform security assessments that can verify the integrity and quality of public, open source libraries for safety before they are used.”

Attack Chain Compromised LottiePlayer npm Package supply
Follow on X (Twitter)
Share. Facebook Twitter LinkedIn
Previous ArticleEthereum ETF inflow hit $ 71 million – Can $ 2,900 be the next goal of ETH?
Next Article Why this Bitcoin-Friendly Lawmaker Carries a US Debt Clock in His Pocket

Related Posts

Bitcoin

$1.14 Billion Wiped Out as Market Faces Double Attack? 

15 June 2025
Security and Privacy

Senators Demand Probe into SEC Hack After Bitcoin Price Spike

15 June 2025
Security and Privacy

Inferno Drainer Spoofs Over 100 Crypto Brands to Steal $80m+

15 June 2025
Add A Comment
Leave A Reply Cancel Reply

Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Top Posts
Web3

Earn 5x GUN Tokens Monthly: A Complete Guide to Off the Grid Battle Pass

15 June 2025
Altcoins

Pyth wipes 64% rally – these signs show that bears are not yet ready

22 May 2025
Top Posts

Can Solana Break the $180 Resistance? Here’s What SOL Price Will Be Worth in 2025!

24 May 2025128 Views

Trump Family Backed American Bitcoin To Go Public via Merger With Gryphon Digital

20 May 202516 Views

Wazirx’s Nischal Shetty Reports $478.5m Net Liquid Assets As Voting Starts

20 May 202512 Views

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest
Top Insights

U.S. SEC Postpones Verdict on Dogecoin, Hedera, Avalanche Spot ETFs

13 June 2025

Will CPI Data Trigger a Crypto Crash?

9 June 2025

Is Ethereum the New Wall Street Darling? $743M ETF Inflows Say Yes

5 June 2025
Get Informed

Subscribe to Updates

Spice Up Your Crypto Knowledge – Get the Latest News & Insights Straight to Your Inbox!

Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 thecoinvibe.com - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.