-= Per source details. Do not edit below this line.=-
The NPM package @lottiefiles/lottie-player had unauthorized new versions published that contained malicious code.
The malicious code prompted for users to connect crypto wallets.
{
"malicious-packages-origins": [
{
"sha256": "faa879b0fa360852899250846599b4b81d442b942d5e4fec4101044400272af1",
"versions": [
"2.0.5",
"2.0.6",
"2.0.7"
],
"import_time": "2024-10-31T23:21:21.099965Z",
"source": "google-open-source-security",
"modified_time": "2024-10-31T23:17:47Z"
}
]
}