# Polyfill supply chain attack embeds malware in JavaScript CDN assets

DevFeed: [Polyfill supply chain attack embeds malware in JavaScript CDN assets](<https://devfeed.tech/articles/polyfill-supply-chain-attack-embeds-malware-in-javascript-cdn-assets-8046.md>)

Original publisher: [Read original article](<https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/>)

Author: Liran Tal

Published: 2024-06-26T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [polyfill](<https://devfeed.tech/topics/polyfill.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [Code](<https://devfeed.tech/topics/code.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [polyfill](<https://devfeed.tech/tags/polyfill.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

## AI overview

The article reports a JavaScript polyfill supply-chain attack in which malicious code was embedded in assets served through a CDN after the polyfill project and domain changed ownership. It states that more than 100,000 websites may have been affected and explains how Snyk Code custom rules can detect usage of the affected CDN URL in JavaScript or PHP code.

## Source excerpt

On June 25, 2024, the Sansec security research and malware team announced that a popular JavaScript polyfill project had been taken over by a foreign actor identified as a Chinese-originated company.