June 26th, 2024

"Polyfill.io sold to a weird Chinese company and should no longer be recommended

The GitHub repository contains information about FormatJS and related libraries. Contact for specific details or assistance.

Read original articleLink Icon
"Polyfill.io sold to a weird Chinese company and should no longer be recommended

The content retrieved from the GitHub URL provided pertains to the repository for FormatJS and related libraries. For further details or assistance regarding this repository, feel free to reach out for more specific information.

Link Icon 3 comments
By @acheong08 - 5 months
To be honest, I don’t fault the developer too much for selling out. Offers tend to be very generous and potentially life changing. There was no indication that the acquisition was for malicious means despite being highly suspicious.

I’ve been offered money for control over my PyPi account which I rejected only because I got an Apple security bounty shortly before which funded part of my university costs. I still slightly regret not selling out as it would’ve made my quality of life so much better. E.g. No worrying about the price of food etc.

I do feel bad for the original developer though (it seems the maintainer that sold it is not the original author) who now has their reputation tarnished.

By @lcnPylGDnU4H9OF - 5 months
Recent and related:

Polyfill supply chain attack hits 100K+ sites (1 day ago; 331 comments): https://news.ycombinator.com/item?id=40791829

By @aragonite - 5 months
I've yet to see any evidence that it's a "Chinese company." All indications so far point to it being a Philippine company based in Manila, likely run primarily by native Chinese speakers who conduct their business largely in Chinese. That doesn't make it a "Chinese company" any more than it makes the vast majority of businesses in NYC Chinatown or Flushing, Queens "Chinese companies."

See: https://news.ycombinator.com/item?id=40801999

Edit: The Register has updated their article to be less committal. See the diff at https://www.diffchecker.com/W3wmc71w/