The Polyfill.io software supply chain attack: Lessons learned
ID: 480735d0-05a0-500e-9397-1958a83c4fc8
STIX ID: report--480735d0-05a0-500e-9397-1958a83c4fc8
Feed Name: ReversingLabs Blog
Date Published: 2024-06-28
Date Updated: 2026-04-29
Author: [email protected] (Carolynn van Arsdale)
Sansec disclosed that the community-run Polyfill.io CDN — sold to Funnull — was modified to push malicious JavaScript to sites that embed cdn.polyfill.io, injecting malware on mobile devices and redirecting users to spam; researchers provided IoCs, noted anti-analysis protections in the payload, and advised web maintainers to remove the CDN and use scanning/remediation tools such as Polykill.io.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
