• Welcome to Religious Forums, a friendly forum to discuss all religions in a friendly surrounding.

    Your voice is missing! You will need to register to get access to the following site features:
    • Reply to discussions and create your own threads.
    • Our modern chat room. No add-ons or extensions required, just login and start chatting!
    • Access to private conversations with other members.

    We hope to see you as a part of our community soon!

Malware injected into 100,000 commonly used web sites.

Brickjectivity

Veteran Member
Staff member
Premium Member
Some are government sites.

A relatively unheard of company called Funnull buys a commonly used javascript development company that provides web site services provided on Polyfill.io . These are helper scripts for older browsers. A hundred thousand sites rely upon this javascript which is dynamically loaded when a browser is not up to date. (Perfect hacking targets.) Because of it these sites (some of them official government sites), redirect you to malware sites and crazy advert sites!

"More than 100,000 sites are already carrying the hostile scripts, according to the Sansec security forensics team, which on Tuesday claimed Funnull, a Chinese CDN operator that bought the polyfill.io domain and its associated GitHub account in February, has since been using the service in a supply chain attack."


"Google has taken steps to block ads for e-commerce sites that use the Polyfill.io service after a Chinese company acquired the domain and modified the JavaScript library ("polyfill.js") to redirect users to malicious and scam sites."

 
Top