logo

Polyfill.io, BootCDN, Bootcss, Staticfile attack traced to 1 operator

ID: 4426b028-8f7f-5099-b451-85e1ccd3ef83

STIX ID: report--4426b028-8f7f-5099-b451-85e1ccd3ef83

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-06-28

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

Researchers traced a large-scale JavaScript supply-chain attack—impacting Polyfill.io, BootCDN, Bootcss, and Staticfile—to a single operator after discovering a public GitHub repo that exposed Cloudflare API keys and zone IDs; the compromised CDNs delivered obfuscated malicious code (including a 'check_tiaozhuan' redirect function) and evidence suggests the campaign has been active since at least June 2023 and may have affected tens of millions of websites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.