Polyfill, Cloudflare trade barbs after reports of supply chain attack threatening 100k websites
ID: f1a08cbc-ab0f-5893-9401-bcc771939965
STIX ID: report--f1a08cbc-ab0f-5893-9401-bcc771939965
Feed Name: The Record from Recorded Future News
Researchers and Cloudflare say the popular polyfill.io service was taken over and used to inject malicious JavaScript into sites that load the library, redirecting mobile users (e.g., to fraudulent sports betting sites) and enabling broader malware distribution; Cloudflare and Sansec confirmed active abuse and urged immediate removal of polyfill, while the incident highlights open-source supply-chain risks and calls for better vetting and sustainability for widely used projects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
