Namecheap Takes Down Polyfill.io Service Following Supply Ch...
Blog post from Socket
Namecheap has taken down the Polyfill.io service after it was discovered to have been serving malware through its CDN for several months, following the sale of the service to a Chinese company named Funnull. This supply chain attack affected over 110,000 websites, including prominent organizations and government sites, by redirecting mobile users to a fraudulent sports betting site. The attack was facilitated by dynamically generated polyfill code that evaded detection and targeted specific mobile devices. The situation has prompted warnings from various tech entities, urging users to cease using the compromised CDN immediately. The original polyfill.js library, initially designed to ensure compatibility of web applications with older browsers, has been moved to alternative hosts like Cloudflare and Fastly to mitigate security risks. The incident has also sparked discussions on the challenges faced by open source maintainers, highlighting issues like burnout and the need for sustainable funding from companies that rely on open source projects.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.