Skip Navigation
Hacker News @lemmy.smeargle.fans bot @lemmy.smeargle.fans
BOT

If you're using Polyfill.io code on your site – remove it immediately

www.theregister.com Remove Polyfill.io code from your website immediately

Scripts turn malicious, infect webpages after Chinese CDN swallows domain

Remove Polyfill.io code from your website immediately
4

You're viewing a single thread.

4 comments
  • You start to wonder how many CDN's have been compromised in the past, or if they have actually been discovered. Maybe this company did it the stupid way and got caught and someone else has not been caught.

    Also, aren't there sum checkings implemented client side, or does the server give you the sum if you select the "latest" tag? I seem to remember there was some sort of checking, but I dunno.

    • This one was a known bad actor, one of the polyfill devs has been warning since February. But people blindly used the cdn anyway

      • Ok, then let's not think about it then. Seems like a good idea... /s