Polyfill.io Supply Chain Attack

Description

CyStack identified the usage of Pollyfill library on the web site. Polyfill, a widely used JavaScript library, was compromised following its acquisition by Funnull, a China-based CDN company. Malicious code was injected into the library, redirecting users to harmful websites.

Remediation

Remove polyfill.io from the website and replace it with secure alternatives provided by Cloudflare and Fastly.

Try Deep Scan Version

Give your DevOps team the freedom to innovate and create outstanding products without being held back by security concerns.