Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Namecheap Takes Down Polyfill.io Service Following Supply Ch...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
1,024
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Namecheap has taken down the Polyfill.io service after it was discovered to have been serving malware through its CDN for several months, following the sale of the service to a Chinese company named Funnull. This supply chain attack affected over 110,000 websites, including prominent organizations and government sites, by redirecting mobile users to a fraudulent sports betting site. The attack was facilitated by dynamically generated polyfill code that evaded detection and targeted specific mobile devices. The situation has prompted warnings from various tech entities, urging users to cease using the compromised CDN immediately. The original polyfill.js library, initially designed to ensure compatibility of web applications with older browsers, has been moved to alternative hosts like Cloudflare and Fastly to mitigate security risks. The incident has also sparked discussions on the challenges faced by open source maintainers, highlighting issues like burnout and the need for sustainable funding from companies that rely on open source projects.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.