The Polyfill supply chain cyberattack was one of the most widespread cyberthreats of 2024, affecting over 100,000 websites worldwide . Initially attributed to Chinese actors , the incident has now been linked to North Korean hackers. The revelations highlight the growing role of state-linked cyberattack groups in the global digital ecosystem and highlight how vulnerable even a key internet infrastructure service can become.
See also: Open VSX: Supply Chain attack distributes GlassWorm via compromised dev account

How the crisis at the Polyfill service began
In February 2024, the popular service Polyfill.io , which provides JavaScript code to ensure compatibility of websites with different browsers, was acquired by the Chinese CDN company Funnull . Shortly after the acquisition, security researchers noticed that scripts distributed through the domain cdn.polyfill.io had been modified . embedded Malicious JavaScript was within the code , which was selectively activated and mainly targeted mobile users. The malicious script used detection evasion techniques and redirected visitors to gambling or adult content sites . In June 2024, cybersecurity companies confirmed the malicious activity, causing great concern in the developer community.
More than 100,000 websites exposed
The attack quickly gained massive proportions because the Polyfill library is widely used on websites around the world. Thousands of businesses, online stores and services were incorporating the script for compatibility reasons without knowing that it had been turned into a carrier of malicious code. It is estimated that over 100,000 websites were directly affected. The revelation led to mass recommendations for website administrators to immediately remove any reference to the Polyfill domain, in order to limit the risk of further exploitation. At the same time, major technology companies took their own protective measures, blocking suspicious activity and warning users.
See also: Supply Chain Threat Protection: New security solution from SpyCloud

New evidence reveals North Korean involvement
Although Funnull’s involvement had led many experts to conclude that it was a Chinese company , a recent investigation has revealed new evidence. The cybersecurity firm Hudson Rock , which specializes in analyzing data collected by infostealer malware, has identified evidence linking the case to North Korean hackers . According to the investigation, a hacker downloaded a fake software installer that installed the LummaC2 malware . The malware collected credentials, browser logs, and other sensitive data from the infected computer. The stolen data included access credentials to Funnull ’s DNS management systems as well as Polyfill ’s administrative accounts , creating a strong chain of evidence linking the two parties.
Cryptocurrencies, online gambling and financial incentives
Researchers believe that the campaign was not limited to simple user redirects. A possible goal was to channel traffic to online gambling platforms connected to Chinese company networks. Through this ecosystem, huge volumes of cryptocurrencies could be converted and channeled back to North Korean financing mechanisms. Cyberattacks are also a key source of revenue for North Korea. Analysts estimate that in 2025 alone, hacking groups linked to the country managed to extract digital assets worth more than two billion dollars.
See also: New malicious packages revealed in NuGet Supply Chain Attack

Penetration into technology companies
The data collected also revealed a separate cyber espionage. In it, a North Korean agent managed to secure a job at a major cryptocurrency exchange using a fake identity. Through access to the company’s internal systems, he gathered information about detection and prevention procedures money laundering. The case shows that modern cyber threats are no longer limited to technical software attacks, but combine social engineering, financial networks and state strategy to finance covert activities.
What it means for internet security
The Polyfill case serves as a reminder that even small pieces of code that are used in large numbers can be turned into large-scale weapons. For organizations and developers, continuous monitoring of software dependencies is now becoming a critical security factor.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
