UNCOS

384,000 sites pull code from sketchy code library recently bought by Chinese firm

384,000 sites pull code from sketchy code library recently bought by Chinese firm

image via Ars Technica

July 3, 2024, 7:36 PM

  • More than 384,000 websites are still linking to a site that was caught last week performing a supply-chain attack that redirected visitors to malicious sites.
  • The site, polyfill[.]com, was a legitimate open source project that allowed older browsers to handle advanced functions that weren’t natively supported.
  • In February, China-based company Funnull acquired the domain and the GitHub account that hosted the JavaScript code. On June 25, researchers from security firm Sansec reported that code hosted on the polyfill domain had been changed to redirect users to adult- and gambling-themed websites.

More than 384,000 websites are still linking to a site that was caught last week performing a supply-chain attack that redirected visitors to malicious sites. The sites include those of Hulu, Mercedes-Benz, and Warner Bros. and the federal government. Researchers say the attack was possible because the site was a legitimate open source project that allowed older browsers to handle advanced functions that weren't natively supported.

Read original article

Entities Mentioned

Dan GoodinAndrew BettsAidan HollandFunnull

Topics Covered

Biz & ITSecurity

Comments (0)

No comments yet.