flawopen.com/Teardowns/polyfill-io-supply-chain-hijack

● CVE-2024-0000 · CVSS 9.8 · 严重
安全研究 · FlawOpen

深度技术拆解:CVE Teardown: Polyfill.io Supply Chain Hijack (Over 100k Sites Compromised)

CVE-2024-0000 源代码级技术深度解析与系统加固工程指南:深入剖析漏洞触发条件、攻击利用链条与加固补丁的具体实现。

💡 通俗易懂的原理解析 (ELI5)

设想成千上万家餐厅多年来一直雇佣同一家值得信赖的送水快递服务。当原快递员退休并秘密将业务出售给无良竞争对手后,新司机开始在暗中查看餐桌,并悄悄将假冒的赌场抽奖券塞入特定移动端顾客的饮料中。

核心概念与专有名词

Dynamic User-Agent Polyfilling
技术概念 (Dynamic User-Agent Polyfilling):Serving tailored JavaScript bundles depending on the client's browser headers, making Subresource Integrity (SRI) hashes impossible.
Conditional Payload Evasion
技术概念 (Conditional Payload Evasion):Analyzing HTTP Referer, screen size, user-agent, and devtools presence to serve clean scripts to developers while attacking real mobile consumers.
Domain Ownership Transfer Risk
技术概念 (Domain Ownership Transfer Risk):The inherent danger of embedding third-party scripts from domains that can be acquired, expired, or transferred without consent.
Subresource Integrity (SRI)
技术概念 (Subresource Integrity (SRI)):A cryptographic browser mechanism that validates script hashes before execution.

根本原因剖析 (Root Cause)

根本原因在于开源系统中未经验证的边界参数,导致状态不同步并绕过安全控制。

攻击执行流程分解

Step 1

1. Domain Acquisition

In February 2024, the domain polyfill.io was purchased from its creator by Funnull, an operator associated with casino affiliate marketing.

Step 2

2. User-Agent & Header Filtering

The CDN edge inspected incoming HTTP requests. If the request was from an admin IP, Google bot, or desktop browser with DevTools open, it served normal, benign polyfills.

Step 3

3. Targeted Evasion & Payload Delivery

If the request was from an organic mobile visitor via search referrer, the server appended an obfuscated redirect payload: window.location.href = 'https://kucontent.com/...'.

Step 4

4. Ecosystem Interventions

Cloudflare and Fastly deployed automatic edge URL rewrites to replace polyfill.io with clean mirrors, while Google flagged all sites utilizing the script in search results.

源代码对比:漏洞与安全实现

✕ 存在漏洞的实现
<!-- VULNERABLE: Direct 3rd-party CDN script without integrity verification -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- Polyfill CDN serves arbitrary dynamic code controlled by third party -->
  <script src="https://cdn.polyfill.io/v3/polyfill.min.js?features=default,Array.prototype.flat"></script>
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>
✓ 加固后的安全修复
<!-- SECURE: Native ES6+ or Self-Hosted Vendored Fallbacks with CSP & SRI -->
<!DOCTYPE html>
<html>
<head>
  <title>Production Web App</title>
  <!-- 1. Modern browsers require no polyfills (99%+ modern baseline) -->
  <!-- 2. For legacy needs, bundle polyfills locally into your build pipeline -->
  <script src="/static/vendor/core-js-bundle.min.js" 
          integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC" 
          crossorigin="anonymous"></script>

  <!-- 3. Strict Content Security Policy blocking untrusted third-party script sources -->
  <meta http-equiv="Content-Security-Policy" 
        content="default-src 'self'; script-src 'self' 'sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC';">
</head>
<body>
  <h1>Welcome</h1>
</body>
</html>

工程与系统安全加固清单