logo

Polyfill[.]io Attack Impacts Over 380,000 Hosts, Including Major Companies

ID: b0f4cf4b-7700-5c48-8599-51651bc9b599

STIX ID: report--b0f4cf4b-7700-5c48-8599-51651bc9b599

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-07-05

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

The Polyfill.io JavaScript library was compromised after its domain and repository changed hands, and malicious code was introduced that conditionally redirects visitors to adult and gambling sites; Censys identified over 380,000 hosts embedding the malicious polyfill endpoints and linked maintainers to a broader set of suspicious domains and 1.6M public-facing hosts, while registrars, CDNs, and security vendors have taken mitigations and warned of impacted packages and plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.