Bitcoin
Bitcoin (BTC)
$63,477.00 2.41155
Bitcoin price
Ethereum
Ethereum (ETH)
$1,671.67 2.41161
Ethereum price
XRP
XRP (XRP)
$1.14 3.37886
XRP price
BNB
BNB (BNB)
$603.67 2.29808
BNB price
Solana
Solana (SOL)
$66.96 3.9638
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.97 10.00261
Hyperliquid price
Cardano
Cardano (ADA)
$0.170775 5.29322
Cardano price
Chainlink
Chainlink (LINK)
$7.90 3.49589
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.074384 2.67446
POL (ex-MATIC) price
Toncoin
Toncoin (TON)
$1.73 7.28684
Toncoin price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000945 -22.70024
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$63,477.00 2.41155
Bitcoin price
Ethereum
Ethereum (ETH)
$1,671.67 2.41161
Ethereum price
XRP
XRP (XRP)
$1.14 3.37886
XRP price
BNB
BNB (BNB)
$603.67 2.29808
BNB price
Solana
Solana (SOL)
$66.96 3.9638
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.97 10.00261
Hyperliquid price
Cardano
Cardano (ADA)
$0.170775 5.29322
Cardano price
Chainlink
Chainlink (LINK)
$7.90 3.49589
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.074384 2.67446
POL (ex-MATIC) price
Toncoin
Toncoin (TON)
$1.73 7.28684
Toncoin price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000945 -22.70024
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$63,477.00 2.41155
Bitcoin price
Ethereum
Ethereum (ETH)
$1,671.67 2.41161
Ethereum price
XRP
XRP (XRP)
$1.14 3.37886
XRP price
BNB
BNB (BNB)
$603.67 2.29808
BNB price
Solana
Solana (SOL)
$66.96 3.9638
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.97 10.00261
Hyperliquid price
Cardano
Cardano (ADA)
$0.170775 5.29322
Cardano price
Chainlink
Chainlink (LINK)
$7.90 3.49589
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.074384 2.67446
POL (ex-MATIC) price
Toncoin
Toncoin (TON)
$1.73 7.28684
Toncoin price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000945 -22.70024
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$63,477.00 2.41155
Bitcoin price
Ethereum
Ethereum (ETH)
$1,671.67 2.41161
Ethereum price
XRP
XRP (XRP)
$1.14 3.37886
XRP price
BNB
BNB (BNB)
$603.67 2.29808
BNB price
Solana
Solana (SOL)
$66.96 3.9638
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.97 10.00261
Hyperliquid price
Cardano
Cardano (ADA)
$0.170775 5.29322
Cardano price
Chainlink
Chainlink (LINK)
$7.90 3.49589
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.074384 2.67446
POL (ex-MATIC) price
Toncoin
Toncoin (TON)
$1.73 7.28684
Toncoin price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000945 -22.70024
Asteroid Shiba price

SaaS animation platform LottieFiles alerts users to crypto threats

Dorian Batycka
Edited by
News
SaaS animation platform LottieFiles alerts users to crypto threats

LottieFiles revealed a supply chain compromise in which malicious code could lure users into connecting crypto wallets, potentially leading to asset theft.

LottieFiles, a platform that enables designers and developers to create animations, has issued a warning regarding a security breach involving its npm package, which may expose users to malicious code designed to compromise crypto wallets.

In an X post on Oct. 31, LottieFiles said that the affected versions — Lottie Web Player 2.0.5, 2.0.6, and 2.0.7 — were released on Oct. 30, prompting immediate concerns after multiple user reports surfaced about strange code injections. In response to the threat, LottieFiles released a new version, 2.0.8, reverting to the secure code.

“A large number of users using the library via third-party CDNs without a pinned version were automatically served the compromised version as the latest release.”

LottieFiles

For those unable to update, LottieFiles recommends informing end users about potential fraudulent wallet connection prompts associated with the Lottie-player. Users may also opt to remain on version 2.0.4 to avoid risk.

LottieFiles warned that applications using the compromised npm package may inadvertently prompt users to connect their crypto wallets, opening avenues for potential theft. The developer account linked to the malicious uploads has been stripped of access, and related tokens have been revoked to halt any further unauthorized activity, the firm added, though the full extent of the attack remains unknown.