384,000 sites pull code from sketchy code library recently bought by Chinese firm
image via Ars Technica
July 3, 2024, 7:36 PM
- •More than 384,000 websites are still linking to a site that was caught last week performing a supply-chain attack that redirected visitors to malicious sites.
- •The site, polyfill[.]com, was a legitimate open source project that allowed older browsers to handle advanced functions that weren’t natively supported.
- •In February, China-based company Funnull acquired the domain and the GitHub account that hosted the JavaScript code. On June 25, researchers from security firm Sansec reported that code hosted on the polyfill domain had been changed to redirect users to adult- and gambling-themed websites.
More than 384,000 websites are still linking to a site that was caught last week performing a supply-chain attack that redirected visitors to malicious sites. The sites include those of Hulu, Mercedes-Benz, and Warner Bros. and the federal government. Researchers say the attack was possible because the site was a legitimate open source project that allowed older browsers to handle advanced functions that weren't natively supported.
Entities Mentioned
Dan GoodinAndrew BettsAidan HollandFunnull
Topics Covered
Biz & ITSecurity
Comments (0)
No comments yet.