flawopen.com/Teardowns/polyfill-io-supply-chain-hijack

● CVE-2024-0000 · CVSS 9.8 · Критический
Исследования · FlawOpen

Технический разбор: CVE Teardown: Polyfill.io Supply Chain Hijack (Over 100k Sites Compromised)

Технический анализ исходного кода и защитные инженерные меры для vulnerabilidade: How the acquisition of the popular polyfill.io domain by a gambling/redirect syndicate turned a ubiquitous frontend CDN into a stealthy, conditional malware injector.

💡 Простыми словами (ELI5)

Представьте тысячи ресторанов, годами заказывавших воду у одной надежной службы курьеров. Когда прежний курьер ушел на пенсию и тайно продал бизнес мошенникам, новый водитель стал проверять столики и подсовывать фальшивые лотерейные билеты в напитки посетителей.

Ключевые понятия и термины

Dynamic User-Agent Polyfilling
Технический термин (Dynamic User-Agent Polyfilling): Serving tailored JavaScript bundles depending on the client's browser headers, making Subresource Integrity (SRI) hashes impossible.
Conditional Payload Evasion
Технический термин (Conditional Payload Evasion): Analyzing HTTP Referer, screen size, user-agent, and devtools presence to serve clean scripts to developers while attacking real mobile consumers.
Domain Ownership Transfer Risk
Технический термин (Domain Ownership Transfer Risk): The inherent danger of embedding third-party scripts from domains that can be acquired, expired, or transferred without consent.
Subresource Integrity (SRI)
Технический термин (Subresource Integrity (SRI)): A cryptographic browser mechanism that validates script hashes before execution.

Анализ первопричины

Основная причина заключается в невалидированных граничных параметрах в системах с открытым исходным кодом, что приводит к рассинхронизации состояний и обходу средств безопасности.

Пошаговый сценарий атаки

Step 1

1. Domain Acquisition

In February 2024, the domain polyfill.io was purchased from its creator by Funnull, an operator associated with casino affiliate marketing.

Step 2

2. User-Agent & Header Filtering

The CDN edge inspected incoming HTTP requests. If the request was from an admin IP, Google bot, or desktop browser with DevTools open, it served normal, benign polyfills.

Step 3

3. Targeted Evasion & Payload Delivery

If the request was from an organic mobile visitor via search referrer, the server appended an obfuscated redirect payload: window.location.href = 'https://kucontent.com/...'.

Step 4

4. Ecosystem Interventions

Cloudflare and Fastly deployed automatic edge URL rewrites to replace polyfill.io with clean mirrors, while Google flagged all sites utilizing the script in search results.

Исходный код: Уязвимый vs Защищённый вариант

✕ УЯЗВИМАЯ РЕАЛИЗАЦИЯ
<!-- VULNERABLE: Direct 3rd-party CDN script without integrity verification -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- Polyfill CDN serves arbitrary dynamic code controlled by third party -->
  <script src="https://cdn.polyfill.io/v3/polyfill.min.js?features=default,Array.prototype.flat"></script>
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>
✓ БЕЗОПАСНЫЙ ИСПРАВЛЕННЫЙ ВАРИАНТ
<!-- SECURE: Native ES6+ or Self-Hosted Vendored Fallbacks with CSP & SRI -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- 1. Modern browsers require no polyfills (99%+ modern baseline) -->
  <!-- 2. For legacy needs, bundle polyfills locally into your build pipeline -->
  <script src="/static/vendor/core-js-bundle.min.js" 
          integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC" 
          crossorigin="anonymous"></script>

  <!-- 3. Strict Content Security Policy blocking untrusted third-party script sources -->
  <meta http-equiv="Content-Security-Policy" 
        content="default-src 'self'; script-src 'self' 'sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC';">
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>

Чек-лист по защите системы для инженеров