July 3rd, 2024

Many website admins have yet to get memo to remove Polyfillio links

More than 384,000 websites linked to a code library involved in a supply-chain attack by a Chinese firm. Industry responses included domain suspensions and ad blocks. Over 1.6 million sites linked to potentially malicious domains. The incident highlights supply-chain attack risks.

Read original articleLink Icon
Many website admins have yet to get memo to remove Polyfillio links

More than 384,000 websites were found linking to a code library that was recently involved in a supply-chain attack after being acquired by a Chinese firm. The JavaScript code hosted on polyfill[.]io was altered to redirect users to adult and gambling sites. Industry responses included domain suspensions, content delivery networks replacing links, and ad blocks. Despite these actions, over 384,000 sites, including mainstream companies like Hulu and Mercedes-Benz, continued to link to the compromised site. Additionally, an Internet scan revealed over 1.6 million sites linking to domains owned by the same entity, with potential malicious activities. Censys researchers highlighted the risk of similar attacks on associated domains. The majority of sites linking to the compromised library were hosted by a German web host. The incident underscores the threat of supply-chain attacks, which can impact a large number of users by infecting a common source. Efforts to contact the Chinese firm, Funnull, for comment were unsuccessful.

Link Icon 1 comments