Supply chain attack on lottie-player: everything you need to know
Summary
Wiz analyzes the lottie-player supply chain attack: malicious versions 2.0.5–2.0.7 prompted Web3 wallet drains after a maintainer token was compromised, impacting 1inch via CDN-hosted copies.
- Published
- Collected
Skip to content