flawopen.com/Teardowns/polyfill-io-supply-chain-hijack

● CVE-2024-0000 · CVSS 9.8 · Kritisch
Sicherheitsforschung · FlawOpen

CVE Teardown: Polyfill.io Supply Chain Hijack (Over 100k Sites Compromised)

Detaillierte technische Quellcode-Analyse und Härtungsmaßnahmen für vulnerabilidade: How the acquisition of the popular polyfill.io domain by a gambling/redirect syndicate turned a ubiquitous frontend CDN into a stealthy, conditional malware injector.

💡 Einfache Erklärung (ELI5)

Stellen Sie sich vor, Tausende von Restaurants nutzen seit Jahren denselben vertrauenswürdigen Botendienst für Trinkwasser. Als der ursprüngliche Bote in den Ruhestand ging und die Route heimlich an einen betrügerischen Konkurrenten verkaufte, begann der neue Fahrer, gefälschte Lotteriescheine in die Gläser bestimmter Gäste zu stecken.

Kernkonzepte & Begriffe

Dynamic User-Agent Polyfilling
Bereitstellung maßgeschneiderter JavaScript-Pakete abhängig von den Browser-Headern des Clients, wodurch Subresource Integrity (SRI)-Hashes unmöglich werden.
Conditional Payload Evasion
Analyse von Referer, Bildschirmgröße, User-Agent und Entwicklertools, um Entwicklern saubere Skripte bereitzustellen, während echte mobile Endnutzer angegriffen werden.
Domain Ownership Transfer Risk
Die inhärente Gefahr beim Einbinden von Drittanbieter-Skripten von Domains, die ohne Zustimmung erworben, abgelaufen oder übertragen werden können.
Subresource Integrity (SRI)
Ein kryptografischer Browsermechanismus, der Skripthashes vor der Ausführung validiert.

Ursachenanalyse

Die Grundursache liegt in nicht validierten Grenzparametern in Open-Source-Systemen, die eine Zustandsdesynchronisation und die Umgehung von Sicherheitskontrollen ermöglichen.

Schritt-für-Schritt Angriffsablauf

Step 1

1. Domain Acquisition

In February 2024, the domain polyfill.io was purchased from its creator by Funnull, an operator associated with casino affiliate marketing.

Step 2

2. User-Agent & Header Filtering

The CDN edge inspected incoming HTTP requests. If the request was from an admin IP, Google bot, or desktop browser with DevTools open, it served normal, benign polyfills.

Step 3

3. Targeted Evasion & Payload Delivery

If the request was from an organic mobile visitor via search referrer, the server appended an obfuscated redirect payload: window.location.href = 'https://kucontent.com/...'.

Step 4

4. Ecosystem Interventions

Cloudflare and Fastly deployed automatic edge URL rewrites to replace polyfill.io with clean mirrors, while Google flagged all sites utilizing the script in search results.

Quellcode: Verwundbar vs. Sicher

✕ VERWUNDBARE IMPLEMENTIERUNG
<!-- VULNERABLE: Direct 3rd-party CDN script without integrity verification -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- Polyfill CDN serves arbitrary dynamic code controlled by third party -->
  <script src="https://cdn.polyfill.io/v3/polyfill.min.js?features=default,Array.prototype.flat"></script>
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>
✓ GEHÄRTETER SICHERHEITS-PATCH
<!-- SECURE: Native ES6+ or Self-Hosted Vendored Fallbacks with CSP & SRI -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- 1. Modern browsers require no polyfills (99%+ modern baseline) -->
  <!-- 2. For legacy needs, bundle polyfills locally into your build pipeline -->
  <script src="/static/vendor/core-js-bundle.min.js" 
          integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC" 
          crossorigin="anonymous"></script>

  <!-- 3. Strict Content Security Policy blocking untrusted third-party script sources -->
  <meta http-equiv="Content-Security-Policy" 
        content="default-src 'self'; script-src 'self' 'sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC';">
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>

Checkliste für Engineering & Systemsicherheit