On 30 October 2024, attackers used a compromised npm access token belonging to a LottieFiles developer to publish three malicious versions of @lottiefiles/lottie-player, a widely used web component for showing Lottie animations. Versions 2.0.5, 2.0.6 and 2.0.7 injected a crypto wallet drainer into every website that loaded them, showing visitors fake prompts to connect their wallets. Sites that pulled the player from public CDNs without pinning a version received the malicious code automatically. Users reported strange pop-ups the same day, and LottieFiles released a clean 2.0.8, revoked the developer's access and tokens and had the bad versions removed. Web3 security firm Scam Sniffer reported that one victim lost 10 Bitcoin, worth about $723,000 at the time. LottieFiles has not said how the token was stolen, and its dotLottie player and SaaS platform were not affected.
Key takeaways
- LottieFiles says versions 2.0.5, 2.0.6 and 2.0.7 of its Lottie web player were published to npm "using a compromised access token from a developer with the required privileges."
- The injected code displayed fake wallet connection prompts and tried to drain assets from visitors who connected. BleepingComputer confirmed it loaded a crypto drainer.
- Lottie Player had about 94,000 weekly downloads and more than 4 million lifetime downloads, according to Wiz. Scam Sniffer reported one victim losing 10 Bitcoin; LottieFiles has not confirmed the total number of victims or losses.
- This was a confirmed breach. LottieFiles removed the compromised account's access and tokens, published 2.0.8 and asked npm to unpublish the malicious versions.
- The identity lesson: a single developer token with publish rights can push code into thousands of websites, so publishing tokens need the same protection, scoping and expiry as production secrets.
At a glance
| Organisations | LottieFiles; websites and web apps that loaded @lottiefiles/lottie-player, including 1inch, according to Wiz and TechTarget |
|---|---|
| When | Malicious versions published on 30 October 2024; discovered the same day after user reports; LottieFiles statement 31 October 2024 |
| Attacker | Unknown. No public attribution |
| Entry point | A compromised npm access token belonging to a LottieFiles developer with publishing rights; how it was obtained has not been disclosed |
| Identities abused | The developer's npm access token used to publish the package |
| Impact | Wallet drainer served to visitors of sites using the player; one reported loss of 10 Bitcoin (about $723,000), unconfirmed by LottieFiles; total victims unknown |
| Category | NHI. Incident class: confirmed NHI breach (stolen npm publishing token used to ship a wallet drainer) |
What happened
LottieFiles provides tools for the Lottie animation format, and its lottie-player web component lets websites embed those animations. Many sites load it straight from public CDNs such as unpkg and jsDelivr, often using the latest tag rather than a fixed version. Wiz says the library had more than 4 million lifetime uses and about 94,000 weekly downloads. The three malicious releases were, according to The Register, the project's first changes in two months.
On 30 October 2024, new versions appeared on npm. Wiz puts their publication between 8:12pm and 9:57pm GMT that day. In its incident statement on GitHub, LottieFiles wrote that "Versions 2.0.5, 2.0.6, 2.0.7 were published directly to npmjs.com over the course of an hour using a compromised access token from a developer with the required privileges." Wiz says the token belonged to a library maintainer. The injected code showed visitors a Web3 wallet connection pop-up. BleepingComputer tested the script and found that clicking the connect button opened a WebSocket connection to castleservices01[.]com, a domain previously tied to crypto phishing, and tried to drain assets and NFTs. DeFi platform 1inch warned that users of its web app may have seen a malicious wallet connection and signature request between 9:12pm and 11:22pm CET, according to TechTarget.
BleepingComputer reports that the problem came to light on 30 October following multiple user reports of unexpected pop-ups. LottieFiles activated its incident response plan, brought in an external incident response team, removed the compromised account's access and tokens, and published 2.0.8, a copy of the last clean version, 2.0.4. Co-founder and CTO Nattu Adnan told The Register: "This does not impact our dotlottie player and/or SaaS services."
LottieFiles has not said how the developer's token was compromised. Checkmarx researcher Jossef Harush suggested to The Hacker News that the attackers bypassed two-factor authentication: "Even with 2FA configured, the threat actors somehow got the npm automation token set in the CI/CD pipeline." That is a researcher's view and has not been confirmed by LottieFiles.
Timeline
| Date | Event |
|---|---|
| March 2024 | Version 2.0.4, the last clean release before the attack, is published, according to The Register. |
| 30 October 2024 | Versions 2.0.5, 2.0.6 and 2.0.7 are published to npm with a compromised developer token, between 8:12pm and 9:57pm GMT according to Wiz. |
| 30 October 2024 | Users report crypto wallet pop-ups on sites using the player; 1inch warns its web app users. |
| 31 October 2024 | LottieFiles publishes its incident statement, releases 2.0.8 and has the malicious versions removed; Wiz, BleepingComputer and The Register report the attack. |
How it happened: the identity attack path
- Obtain a publishing token. The attacker gained a valid npm access token belonging to a LottieFiles developer with publish rights. How is not public.
- Publish as the developer. Using the token, the attacker pushed three new versions directly to npm, bypassing the project's normal source and review process.
- Ride the CDNs. Sites loading the unpinned
latestversion from public CDNs served the malicious code to their own visitors without any change on their side. - Phish visitors' wallets. The injected script showed a fake wallet connection prompt and requested signatures that would let the attacker drain assets.
- Revocation. LottieFiles removed the developer's access and tokens, republished clean code and had the malicious versions taken down.
Impact
- Confirmed: three malicious package versions were published with a compromised developer token, and visitors to affected sites were shown wallet-draining prompts, according to LottieFiles and BleepingComputer's own test.
- Reported loss: Scam Sniffer reported one victim losing 10 Bitcoin, worth about $723,000, as reported by Wiz and BleepingComputer. The Register notes LottieFiles had not confirmed this. The total number of victims is unknown.
- Not affected: LottieFiles' dotLottie player, SaaS platform, other open source libraries and GitHub repositories, according to the company.
- Potential: sites that explicitly reference 2.0.5, 2.0.6 or 2.0.7, or cache them, stay at risk until they update or revert.
What this means for NHI governance
The Lottie Player attack did not need any flaw in the code. It needed one credential: a developer's npm token that could publish the package. That token is a non-human identity with reach into every website that trusts the package, and it is often long-lived, stored in a developer's machine or a CI pipeline and never reviewed. Whether it was taken from a laptop, a pipeline or a session, the registry accepted it as the developer.
The fix is to treat publishing credentials as high-value secrets. Use short-lived, scoped tokens or trusted publishing from CI, restrict which tokens can publish which packages, and watch for releases that do not match a tagged commit. Consumers have a part too: pinning versions and using subresource integrity for third-party scripts would have kept many sites on the clean 2.0.4. The same pattern hit the Solana and Rspack ecosystems weeks later. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.
Recommendations
- Revoke and rotate publishing tokens after any doubt. LottieFiles removed the developer's access and tokens; do the same at the first sign of an unexpected release. See our Leaked Credential Response Playbook.
- Use short-lived, scoped publishing credentials. Prefer trusted publishing from CI with provenance over long-lived personal or automation tokens. See our CI/CD Pipeline Identity Security Guide.
- Keep tokens out of developer machines and logs. Store publishing secrets in a secrets manager and make sure CI does not print them. See our Secrets Management Guide.
- Alert on releases without a matching commit. A new version with no tag, pull request or CI run behind it should page the maintainers.
- Pin third-party scripts. Load fixed versions from CDNs and use subresource integrity hashes so a new release cannot change what visitors run.
- Review who holds publish rights. Limit publish access to the few maintainers and pipelines that need it, and review the list regularly. See our NHI Ownership Guide.
Frequently asked questions
Which Lottie Player versions were compromised?
Versions 2.0.5, 2.0.6 and 2.0.7 of @lottiefiles/lottie-player, published on 30 October 2024. LottieFiles released 2.0.8, a copy of the clean 2.0.4, and the malicious versions were removed from npm and major CDNs.
How was Lottie Player compromised?
LottieFiles says the attackers used a compromised npm access token belonging to a developer with publishing rights to push the malicious versions directly to npm. The company has not said how the token was obtained.
Did anyone lose money in the Lottie Player attack?
Scam Sniffer reported that one victim lost 10 Bitcoin, worth about $723,000 at the time, after connecting a wallet. LottieFiles has not confirmed this figure or the total number of victims.
Related NHI Mgmt Group resources
Ledger Connect Kit npm compromise 2023 · Solana web3.js npm compromise 2024 · Rspack npm compromise 2024 · CI/CD Pipeline Identity Security Guide · Secrets Management Guide
How NHI Mgmt Group can help
Package publishing tokens are some of the most overlooked non-human identities in a software organisation. We help teams find them, scope them, move to short-lived publishing and build a response plan for when one leaks. See our NHI and AI agent security training.
References
- LottieFiles (GitHub): Malicious code in Lottie-Player CDN files, incident response statement (31 October 2024)
- Wiz: Supply chain attack on lottie-player: everything you need to know (31 October 2024)
- BleepingComputer: LottieFiles hacked in supply chain attack to steal users' crypto (31 October 2024)
- The Register: LottieFiles ends crypto wallet-targeting supply chain attack (31 October 2024)
- The Hacker News: LottieFiles Issues Warning About Compromised 'lottie-player' npm Package (31 October 2024)
- TechTarget: Lottie Player NPM package compromised in supply chain attack (31 October 2024)