Comment on The new Chinese owner of the popular Polyfill JS project injects malware into more than 100 thousand sites

dan@upvote.au ⁨3⁩ ⁨months⁩ ago

My favourite part is that the developers that currently own it said:

Someone has maliciously defamed us. We have no supply chain risks because all content is statically cached

github.com/polyfillpolyfill/…/2890#issuecomment-2…

Completely missing the point that they are the supply chain risk, and the fact that malicious code was already detected in their system (to the point where Google started blocking ads for sites that loaded polyfill .io scripts.

source
Sort:hotnewtop