MAL-2024-10301

    Dashboard / Malicious Package / MAL-2024-10301

    MAL-2024-10301

    Published: 31 Oct 2024Last Modified: 31 Oct 2024

    Summary: Malicious code in @lottiefiles/lottie-player (npm)

    Details: Source: google-open-source-security (faa879b0fa360852899250846599b4b81d442b942d5e4fec4101044400272af1) The NPM package @lottiefiles/lottie-player had unauthorized new versions published that contained malicious code. The malicious code prompted for users to connect crypto wallets.

    Affected packages

    Package

    Name: @lottiefiles/lottie-player

    Purl: pkg:npm/%40lottiefiles/lottie-player

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.5
    2.0.6
    2.0.7