logo

Suspicious Polyfill Login Prompts Pop Up on Toshiba, Muji Websites

ID: f038e229-521d-5199-a8c8-f1e4dc51ef01

STIX ID: report--f038e229-521d-5199-a8c8-f1e4dc51ef01

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-06

Date Updated: 2026-06-11

...
...

**Executive summary:** The Polyfill.io CDN has been compromised and is being used to inject malicious JavaScript into a large number of websites (estimated 100,000+), delivering fake sign-in dialogs that harvest credentials; major brands including Toshiba and Muji were observed serving these overlays. The report describes the attack chain, persistent and evolving payloads (redirects, crypto miners, credential harvesting), and provides remediation guidance such as removing Polyfill.io references, self-hosting polyfills or using trusted CDNs with SRI, and enforcing strong Content Security Policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.