logo

Suspicious Polyfill login prompts pop up on Toshiba, Muji websites

ID: 36974bb8-ca92-5da0-ba60-37306893a8e4

STIX ID: report--36974bb8-ca92-5da0-ba60-37306893a8e4

Feed Name: Bleeping Computer

Threat Score
35/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Bill Toulas

...
...

Tech companies including Toshiba and MUJI warned visitors about unexpected browser sign-in prompts generated by the external CDN domain polyfill.io, which recently began responding with HTTP 401 authentication requests after previously hosting malicious scripts in 2024; affected sites have suspended the service and users are advised not to enter credentials, with no confirmed credential theft reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.