Unsolved
10 Elder
•
44K Posts
0
20
Attack hits 100K+ sites
New owners of the Polyfill.io service modified its JavaScript library ("polyfill.js") to redirect users to malicious and scam sites.
Polyfill is a popular library that supports modern web browser functions. More than 110,000 sites that embed this library are impacted by this supply chain attack, Sansec said in a Tuesday report.
The long list of the sites known or believed to have been using the corrupted JavaScript library is here. The malicious code would have redirected browsers to fake, malicious sites instead of to the intended destinations. Read more here and here.
![](https://prod-care-community-cdn.sprinklr.com/community/687062f5-603c-4f5f-ab9d-31aa7cacb376/sig-30752659-8944-4fa0-a046-41b793e139a1-2086367556.jpg)