4 ms·
yes, "https://polyfill.archive.org/v3/polyfill.min.js?features=fetch,IntersectionObserver,ResizeObserver,globalThis,Element.prototype.getAttributeNames,String.p
by qnsc 2y ago
yes, "https://polyfill.archive.org/v3/polyfill.min.js?features=fetch,IntersectionObserver,ResizeObserver,globalThis,Element.prototype.getAttributeNames,String.prototype.startsWith,Array.prototype.flat,Element.prototype.closest,Element.prototype.scroll,Element.prototype.remove,Object.entries,Object.values,Object.fromEntries https://polyfill.archive.org/v3/polyfill.min.js?features=fet..." is the URL with the malicious code
- Shadow1337 2y agoIt looks like it is running the service that was part of the supply chain attacker earlier this year. https://github.com/polyfillpolyfill/polyfill-service/issues/2890 https://github.com/polyfillpolyfill/polyfill-service/issues/...
- abracadaniel 2y agoThat was a DNS hack of polyfill.io though right? This looks like it was/is self hosted.
- jsheard 2y agoThe service was fine, it was the "official" hosted instance of the service which was compromised. IA appears to be running their own instance.
- __jonas 2y agoYeah I'm getting this exact response from the above URL now: https://sourcegraph.com/github.com/polyfillpolyfill/polyfill-service/-/blob/library/src/get_polyfill_string.rs?L415 https://sourcegraph.com/github.com/polyfillpolyfill/polyfill... Seems like they self hosted that service