Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack - Socket
More than 110K websites using the Polyfill.io service have been impacted by a supply chain attack after a Chinese company bought the service earlier this year. The CDN delivered polyfills, JavaScript for providing modern functionality for older browsers.Funnull, the new owners, have been injecting malware on mobile devices via any site that embeds cdn.polyfill.io for months, according to a research report from Sansec;The polyfill code is dynamically generated based on the HTTP headers, so multip...
Read more at socket.dev