logo

Polyfill.io JavaScript supply chain attack impacts over 100K sites

ID: 992f8d4b-82f2-545e-a1dc-e245f39066f7

STIX ID: report--992f8d4b-82f2-545e-a1dc-e245f39066f7

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-06-25

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A supply-chain compromise of the widely used polyfill.io service occurred after the domain was acquired by a Chinese company ('Funnull') and the hosted script was altered to inject malicious code that redirects visitors (especially on specific mobile devices) to scam sites and can deliver malware; this impacts hundreds of thousands of websites that embed cdn.polyfill.io, prompted Cloudflare/Fastly to offer mirrors, and has led Google to notify advertisers and disapprove affected ads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.