One Script Tag Just Pwn'd Over 100,000 Websites

One Script Tag Just Pwn'd Over 100,000 Websites

Source: YouTube · Theo - t3․gg · published Jun 28, 2024 · 16:06

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video details a critical supply chain attack affecting over 100,000 websites after the domain polyfill.io was sold to a Chinese company, which began injecting malicious JavaScript 0:00-0:083:15-3:23. Website owners are urged to immediately remove polyfill.io scripts, as they are largely unnecessary for modern browsers and now pose a severe security risk 0:32-0:41.

Key Takeaways:
• The original creator revealed they never owned the domain, which was acquired by a company named Funnel in February, leading to a loss of control over the service 5:12-5:18.
• Major sites like JSTOR, Intuit, and Hulu were compromised, with the malware specifically targeting mobile users to redirect them to sports betting sites 0:18-0:227:00-7:09.
• The malicious code is sophisticated, using obfuscated variables and specific triggers like time of day to execute while avoiding detection by admin users 7:11-7:168:02-8:09.
• Google has started blocking ads on affected websites, and even Cloudflare's own status page was found vulnerable before they deployed a fix 4:52-4:5615:03-15:10.
• Cloudflare has launched a feature to automatically rewrite polyfill.io links to a safe mirror for users on their network to mitigate the threat 11:25-11:30.

This incident highlights the inherent risks of third-party scripts and serves as a stark reminder to audit website dependencies regularly [1:05-1:08](https://www.youtube.com

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

if your website uses poly IO remove it immediately I created the polyl service project but I never owned the domain name and I have had no influence over its sale it's hard to know how scary something like this is until we see the impact and although that tweet was in February we've just now seen what they're doing and what they're doing is terrifying hundreds of thousands of websites from into it to J store to Hulu have been pwned by this change that's insane and we need to talk about why and how severe this is so let's go back to the thread from the original Creator and then we'll go through how we got here in the first place no website today requires any of the polyfills in the polyfil io Library most features added to the web platform are quickly adopted by all major browsers with some…