logo

The Polyfill.io software supply chain attack: Lessons learned

ID: 480735d0-05a0-500e-9397-1958a83c4fc8

STIX ID: report--480735d0-05a0-500e-9397-1958a83c4fc8

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2024-06-28

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

Sansec disclosed that the community-run Polyfill.io CDN — sold to Funnull — was modified to push malicious JavaScript to sites that embed cdn.polyfill.io, injecting malware on mobile devices and redirecting users to spam; researchers provided IoCs, noted anti-analysis protections in the payload, and advised web maintainers to remove the CDN and use scanning/remediation tools such as Polykill.io.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.