Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Supply chain attack on lottie-player: everything you need to know

Summary

Wiz analyzes the lottie-player supply chain attack: malicious versions 2.0.5–2.0.7 prompted Web3 wallet drains after a maintainer token was compromised, impacting 1inch via CDN-hosted copies.
Published
Collected

original ↗

Related coverage

back