EddieJayonCrypto

 31 Oct 24

tl;dr

A security breach has impacted multiple decentralized applications (dApps) due to malicious code injected into the widely-used JavaScript animation library, Lottie Player. The attack exploited recent updates to Lottie Player’s npm package, leading to at least one individual losing 10 BTC (US$723,000...

A major security breach has impacted multiple decentralized applications (dApps), with the attack stemming from malicious code injected into Lottie Player, a widely-used JavaScript animation library.

The attack exploited recent updates to Lottie Player’s npm package, specifically in versions 2.0.5 through 2.0.7, where hackers embedded malicious code within JSON files that display animations on websites.

At least one individual has lost 10 BTC (US$723,000) after unknowingly signing a phishing transaction linked to the breach, according to Scam Sniffer, a platform designed to protect users from online fraud.

Blockaid, a cybersecurity platform monitoring the incident, confirmed Wednesday the attackers deployed a fake wallet connection prompt, leading users to the drainer malware "Ace Drainer," which mimics legitimate connections to deceive users.

According to Blockaid, the hackers added harmful code into Lottie Player’s files, turning these animations into entry points for potential scams.

Essentially, when users visited sites with this compromised library, they were shown fake pop-ups asking them to connect their digital wallets. However, these prompts were controlled by hackers and could grant them unauthorized access to users’ funds.

In response to the attack, LottieFiles’ vice president of engineering, Jawish Hameed, confirmed Wednesday that affected versions were removed from npm, and a safe version (2.0.8) was released.

LottieFiles pointed Decrypt to its public statement regarding the breakdown of events when asked for comment. Hameed noted the breach involved the GitHub account of a senior engineer, through which attackers pushed three compromised updates in just three hours on Tuesday.

LottieFiles has since revoked all access from the affected developer account and taken further steps to prevent future incidents.

This type of “supply chain attack”—where hackers infiltrate widely-used software that many websites rely on—can have widespread consequences. In this case, the compromised Lottie Player versions were automatically pulled into many sites, making it easier for hackers to reach users.

Decentralized aggregator platform 1inch, one of the main targets of the attack, reassured users on social media that only its web dApp was affected and that the wallet app and core protocols remain secure.

Security compromises in widely used libraries and tools have become a critical issue as hackers exploit vulnerabilities that allow them access to unsuspecting users’ assets.

Earlier this month, a PEPE token holder lost $1.39 million after unknowingly signing a malicious Permit2 transaction.

More about C3 Ai Inc

C3 Ai Inc (C3) operates in the technology and services-prepackaged software industry with a market capitalization of $3.34 billion. The stock price has shown a 2.28% decrease, closing at $25.11. The Relative Strength Index (RSI) stands at 32.674, indicating a potential oversold condition. The stock has experienced a negative price change of $0.855. The trading volume is at 325,433,000.

Despite the decrease in stock price, the RSI suggests a possible oversold scenario, which could lead to a trend reversal. However, it's important to approach this with caution and wait for confirmation signals to validate a potential bullish reversal. As always, past performance is not indicative of future results, and it's essential to consider all risk factors before making any investment decisions.

Disclaimer

The opinions expressed by the writers at Grow My Bag are their own and do not reflect the official stance of Grow My Bag. The content provided on our site is not intended as investment advice, and Grow My Bag is not an investment advisor. We do not endorse buying or selling any cryptocurrencies or digital assets mentioned in our articles. High-risk investments in Bitcoin, cryptocurrencies, and digital assets require thorough due diligence, and all transfers and trades made are at your own risk. Grow My Bag is not responsible for any potential losses and participates in affiliate marketing.
 22 Nov 24
 22 Nov 24
 22 Nov 24