logo

Polyfill.io Supply Chain Attack

ID: 0bd6d2bd-f924-5717-93eb-0b6e87fe0842

STIX ID: report--0bd6d2bd-f924-5717-93eb-0b6e87fe0842

Feed Name: Qualys Blog

Threat Score
85/100

Date Published: 2024-06-29

Date Updated: 2026-04-28

Author: Sheela Sarva

...
...

A supply-chain compromise of polyfill.js hosted on cdn.polyfill.io (after acquisition by Funnull) resulted in modified scripts that inject malicious code into any site that loads the CDN, causing redirects to scam sites, potential data theft and remote code execution; the report lists impacted domains and IOCs, cites CVE-2024-38526, and provides detection/remediation guidance and Qualys QIDs (including web malware and VM/WAS scans) and recommends removing polyfill.io references and switching to alternative CDNs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.