polyfill-service icon indicating copy to clipboard operation
polyfill-service copied to clipboard

Polyfill.io JavaScript supply chain attack impacts over 100K sites

Open spmedia opened this issue 1 year ago • 10 comments

Reopening this since Polyfill is just closing issues in an attempt to cover this up.

https://www.bleepingcomputer.com/news/security/polyfillio-javascript-supply-chain-attack-impacts-over-100k-sites/

https://sansec.io/research/polyfill-supply-chain-attack

https://www.theregister.com/2024/06/25/polyfillio_china_crisis/

https://www.scmagazine.com/brief/over-100k-sites-hit-by-polyfill-io-supply-chain-attack

spmedia avatar Jun 26 '24 13:06 spmedia

fuck this, github should ban this repo

lovetingyuan avatar Jun 26 '24 14:06 lovetingyuan

what's the status of this?

kingcaubalejo avatar Jun 26 '24 15:06 kingcaubalejo

Previous issue about this: #2890

Daniel15 avatar Jun 26 '24 20:06 Daniel15

Cloudflare is now hosting an alternative service to replace polyfill(.)io

https://blog.cloudflare.com/automatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet/

https://cdnjs.cloudflare.com/polyfill/

ephraimduncan avatar Jun 26 '24 20:06 ephraimduncan

Cloudflare had a polyfill[.]io mirror for a while: https://blog.cloudflare.com/polyfill-io-now-available-on-cdnjs-reduce-your-supply-chain-risk.

What's new is that we are automatically rewriting the insecure polyfill[.]io scripts to our mirror: https://blog.cloudflare.com/automatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet/.

xtuc avatar Jun 26 '24 20:06 xtuc

@lovetingyuan the repo is now flagged

Screenshot_20240628-074159

SkyfallWasTaken avatar Jun 28 '24 06:06 SkyfallWasTaken

what's the status of this?

up!

alvin12 avatar Jun 28 '24 07:06 alvin12

What's new is that we are automatically rewriting the insecure polyfill[.]io scripts to our mirror

How? Are they modifying my files and databases?

krystian3w avatar Jun 28 '24 16:06 krystian3w

@krystian3w if your website is using Cloudflare's cdn and you enabled the polyfill rewriting feature, it will automatically rewrite your scripts tag to point to Cloudflare's fork.

xtuc avatar Jun 28 '24 16:06 xtuc

https://www.bleepingcomputer.com/news/security/polyfillio-bootcdn-bootcss-staticfile-attack-traced-to-1-operator/

spmedia avatar Jun 28 '24 20:06 spmedia