Supply Chain Takeover

CVE Teardown: Polyfill.io Supply Chain Hijack (Over 100k Sites Compromised)

How the acquisition of the popular polyfill.io domain by a gambling/redirect syndicate turned a ubiquitous frontend CDN into a stealthy, conditional malware injector.

💡 Plain English Explainer (ELI5)

For a decade, millions of websites copied and pasted a single line of code: ``. When the original author sold the domain in 2024, the new owners didn't attack security researchers or developers. Instead, their servers checked if a website visitor was on a mobile device during specific hours, and secretly injected malicious redirects to scam casinos.

Core Concepts & Key Terms

Dynamic User-Agent Polyfilling
Serving tailored JavaScript bundles depending on the client's browser headers, making Subresource Integrity (SRI) hashes impossible.
Conditional Payload Evasion
Analyzing HTTP Referer, screen size, user-agent, and devtools presence to serve clean scripts to developers while attacking real mobile consumers.
Domain Ownership Transfer Risk
The inherent danger of embedding third-party scripts from domains that can be acquired, expired, or transferred without consent.
Subresource Integrity (SRI)
A cryptographic browser mechanism that validates script hashes before execution.

Step-by-Step Attack Flow

Step 1

1. Domain Acquisition

In February 2024, the domain polyfill.io was purchased from its creator by Funnull, an operator associated with casino affiliate marketing.

Step 2

2. User-Agent & Header Filtering

The CDN edge inspected incoming HTTP requests. If the request was from an admin IP, Google bot, or desktop browser with DevTools open, it served normal, benign polyfills.

Step 3

3. Targeted Evasion & Payload Delivery

If the request was from an organic mobile visitor via search referrer, the server appended an obfuscated redirect payload: window.location.href = 'https://kucontent.com/...'.

Step 4

4. Ecosystem Interventions

Cloudflare and Fastly deployed automatic edge URL rewrites to replace polyfill.io with clean mirrors, while Google flagged all sites utilizing the script in search results.

Source Code: Flaw vs. Secure Implementation

VULNERABLE PATTERN
<!-- VULNERABLE: Direct 3rd-party CDN script without integrity verification -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- Polyfill CDN serves arbitrary dynamic code controlled by third party -->
  <script src="https://cdn.polyfill.io/v3/polyfill.min.js?features=default,Array.prototype.flat"></script>
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>
HARDENED DEFENSE
<!-- SECURE: Native ES6+ or Self-Hosted Vendored Fallbacks with CSP & SRI -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- 1. Modern browsers require no polyfills (99%+ modern baseline) -->
  <!-- 2. For legacy needs, bundle polyfills locally into your build pipeline -->
  <script src="/static/vendor/core-js-bundle.min.js" 
          integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC" 
          crossorigin="anonymous"></script>

  <!-- 3. Strict Content Security Policy blocking untrusted third-party script sources -->
  <meta http-equiv="Content-Security-Policy" 
        content="default-src 'self'; script-src 'self' 'sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC';">
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>

Engineering Hardening Checklist

← Browse Full Security Directory Explore Reference Blueprints →