HomeSecurityPolyfill.io: Attack affects over 100,000 websites

Polyfill.io: Attack affects over 100,000 websites

Over 100,000 websites have been affected in a supply chain attack by the Polyfill.io service after its domain was acquired by a Chinese company and the script was modified to redirect users to malicious websites.

See also: WordPress plugins at risk – Hackers create fake administrator accounts

Polyfill.io attack

Polyfill.io is code, like JavaScript, that adds modern functionality to older browsers that don't typically support it. For example, it adds JavaScript features that aren't available to older browsers but are present in modern ones.

The polyfill.io service is used by hundreds of thousands of websites to allow all visitors to use the same code base, even if their browsers don't support the same modern features as the newest ones.

Polyfill.io supply chain attack

Today, cybersecurity firm Sansec warned that the polyfill.io domain and service were purchased earlier this year by a Chinese company called “Funnull” and the script has been modified to inject malicious code into websites in a supply chain attack.

“account Github. Since then, this domain has been caught injecting malware into mobile devices via any website that incorporates cdn.polyfill.io,” explains Sansec.

See also: GrimResource: New attack uses MSC files and Windows XSS vulnerability

When polyfill.io was acquired, the project developer warned that he never owned the polyfill.io website and that all websites should immediately remove it. To reduce the risk of a potential supply chain attack, Cloudflare and Fastly created their own mirrors of the Polyfill.io service so that websites could use a trusted service.

supply chain

In recent months, the developer's prediction came true and the polyfill.io service was converted to a CNAME to polyfill.io.bsclink.cn, which the new owners maintain.

When the developers integrated the cdn.polyfill.io scripts into their websites, they saw that the code was coming directly from the Chinese company's website. The developers found that the new owners of polyfill.io had inserted malicious code that redirected visitors to unwanted websites without the website owner's knowledge to carry out the attack.

In one example seen by Sansec, the modified script is primarily used to redirect users to scam websites, such as a fake Sportsbook. It does this via a fake Google analytics domain (www.googie-anaiytics.com) or through redirects such as kuurza.com/redirect?from=bitget.

However, researchers say it was difficult to fully analyze the modified script, as it uses very specific targeting and is resistant to reverse engineering.

Currently, the cdn.polyfill.io domain has mysteriously redirected to Cloudflare's mirror. However, since the domain's DNS servers remain unchanged, owners could easily change it back to their own domains at any time.

See also: Hackers exploit legitimate sites to distribute BadSpace Windows Backdoor

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A supply chain attack, such as the one at Polyfill.io, occurs when an attacker penetrates a system through vulnerabilities in its external providers or suppliers. These attacks can be particularly insidious, as they exploit trusted relationships and can introduce malware. By compromising a link in the supply chain, attackers gain the ability to widely disseminate malicious elements, often remaining unnoticed until significant damage has been caused. In today’s networked world, securing the supply chain is imperative, requiring rigorous auditing procedures , constant monitoring , and strong cybersecurity practices .

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS