Polyfill.io, BootCDN, Bootcss, Staticfile attack traced to 1 operator
ID: 4426b028-8f7f-5099-b451-85e1ccd3ef83
STIX ID: report--4426b028-8f7f-5099-b451-85e1ccd3ef83
Feed Name: Bleeping Computer
Threat Score
Researchers traced a large-scale JavaScript supply-chain attack—impacting Polyfill.io, BootCDN, Bootcss, and Staticfile—to a single operator after discovering a public GitHub repo that exposed Cloudflare API keys and zone IDs; the compromised CDNs delivered obfuscated malicious code (including a 'check_tiaozhuan' redirect function) and evidence suggests the campaign has been active since at least June 2023 and may have affected tens of millions of websites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
