The Polyfill.io supply chain attack, which impacted over 100,000 websites, has been recently linked to North Korean state-sponsored threat actors. While the attack was initially attributed to a Chinese organization, new evidence from an infostealer infection has revealed North Korean involvement in the operation.
Key Details of the Attack
- Origin & Acquisition: In February 2024, the popular Polyfill.io service was acquired by a Chinese company called Funnull. Following the sale, the domain began injecting malicious JavaScript into scripts served to visitors.
- Malicious Activity: The injected code targeted mobile users, redirecting them to gambling, sports betting, or adult websites. The malware was highly sophisticated, using evasion techniques to avoid detection by security scanners.
- North Korean Link: Recent findings by security firm Hudson Rock revealed that a North Korean operative’s device contained credentials for the Funnull DNS management portal and the Polyfill Cloudflare tenant.
- Financial Motive: Experts believe the attack aimed to funnel traffic to gambling sites, which served as a mechanism to launder cryptocurrency back to the North Korean state.
Impact and Remediation
- Affected Sites: Major platforms and government websites were impacted, including Hulu, Mercedes-Benz, WarnerBros, and Intuit.
- Action Taken:
- Domain Takedown: The registrar Namecheap suspended the
polyfill.io domain in June 2024 to mitigate the immediate threat.
- Secure Alternatives: Cloudflare and Fastly created safe, mirrored versions of the Polyfill library to provide secure replacements for developers.
Developers and site owners should immediately remove any references to cdn.polyfill.io and switch to trusted mirrors like the Cloudflare Polyfill Mirror or the Fastly Polyfill Service.