Megathread: Lottiefiles plugin / canvasUI compromised (crypto popups in apps)


this popup is showing in different bubble apps, whats going on???

6 Likes

All apps showing this, bubble got hacked.

Just experienced this. It is the LottieFiles plugin. I removed it and published to fix.

How did you remove it?

Getting this too! I submitted a support ticket. Wow.

IT IS NOT BUBBLE. LottieFiles has been hacked and their javascript was compromised.

TO SOLVE: REMOVE LOTTIE FILES PLUGIN

I don’t have that plugin. It may be more than one thing!

yea what the hell its happenign to me… talk about making your customer sketched out

Yeah, so LottieFiles’s JS was compromised, and to be clear, it’s not Bubble, or the plugin author’s fault.

https://unpkg.com/@lottiefiles/lottie-player@2.0.5/dist/lottie-player.js if you ctrl + F for ‘ethereum’ you’ll see stuff.

Uninstalling the plugin is the best way to fix this immediately, until the maintainers of the JS library fix it. You’ll lose out the animations in your app, but will be able to reinstall the plugin after and everything will be where you left it.

2 Likes

Again, I don’t have that plugin. I think more than one plugin could be at fault here.

3 Likes

Tyr removing the plugin

I was tipped off to the LottieFiles plugin in my app by looking through the console and errors in my browser.

Let’s submit bug reports?

Fixed here after removing the plugin, thanks @nic3

Got it in your HTML headers?

I removed the Lottie Files plugin and it seems to have solved it, also submitted it as a bug.

Defiantly just remove the plugin now if you think you have it installed

2 Likes

i remove the plugin and it still runs

1 Like

I don’t have the plugin

Even Bubble’s main site is affected. Clicking basically anywhere that isn’t inside the editor gives the same screen.

2 Likes

what other plugins use that