Polyfill.io Supply Chain Attack

Sheela Sarva

Last updated on: July 2, 2024

The polyfill.js is a popular open-source library that supports older browsers. Thousands of sites embed it using the cdn[.]polyfill[.]io domain. In February 2024, a Chinese company (Funnull) bought the domain and the GitHub account. The company has modified Polyfill.js so malicious code would be inserted into websites that embedded scripts from cdn.polyfill[.]io. Any script adopted from cdn.polyfill[.]io would immediately download malicious code from the Chinese company’s site. Some of the known outcomes are:

  • user would be redirected to scam sites,
  • allows an attacker to steal sensitive data,
  • potentially perform code execution. 

Given that modern browsers do not require Polyfill, the original polyfill author recommends not to use Polyfill at all. All websites should remove any references to polyfill.io. Recommended alternatives are CDN, such as Cloudflare and Fastly.

Polyfill.io Timeline:

When Would a Website be Compromised?

Efforts Done to Notify Users and Domain Owner:

  • Complaints in GitHub (take precaution going to links listed in the archive): “https://github.com/polyfillpolyfill/polyfill-service/issues/2873”
  • Alerts from Google by blocking sites that use “polyfill.io”
  • Alternate solutions from Cloudflare, Fastly 

Notifications and warnings were ignored, the complaints on GitHub were removed, and the altered script continued to redirect users to malicious sites. 

Secure Your Website with Qualys:

Qualys provides a comprehensive continuous solution to detect security issues in organizations. You can discover all your applications in your organization using CSAM to ensure all the assets are scanned. Given the nature of the attacks possible, we highly recommend organizations to launch VM and WAS scans to detect and remove the usage of scripts from the polyfill.io domain. 

Qualys had existing QIDs that would have informed you of the possibility of the attack. Qualys has kept up with the research and released multiple detections to detect usage of the malicious domain, and sites that have been compromised. If your scans report any of the following QIDs please take immediate action to follow the preventive measures we have provided in your reports. 

VMDR Scan to detect if your assets are vulnerable:

  • QID 731609: Polyfill.io Supply Chain Vulnerability

Web Application Scan to detect if your website is vulnerable:

  • QID 152102: Malicious Polyfill.io Detected
  • QID 151040: Vulnerable JavaScript Detected – Polyfill.js
  • QID 150261: Subresource Integrity (SRI) Not Implemented

           In anticipation of events such as these Qualys research had released a Subresource Integrity check in 2020.

           If you see this IG QID reported, please ensure you take precautions to include integrity attribute to all elements that load external content.

Web Malware Scan to detect malware on your website:

  • QID 207003: A Match to a Known Virus was Detected
  • QID 208000: Content was Loaded from a Remote Malicious Page
  • QID 208001: A Link to a Malicious Page was Found
  • QID 208002: Your Web Site Domain is Blacklisted


Show Comments (1)


Your email address will not be published. Required fields are marked *

  1. how are you validating it is indeed going to “polyfill.io”, there won’t be much evidence available in the detections, if they are using some other CDNs it will be false positive.