* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, December 28, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    Movies and TV shows casting across the US – Wyoming News Now

    Movies and TV shows casting across the US – Wyoming News Now

    Holiday light displays, ice hockey and more things to do this week: Around Baton Rouge – The Advocate

    Brighten Your Week in Baton Rouge: Holiday Light Displays, Ice Hockey, and More Exciting Events

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Sharge Technology Secures Nearly 100M Yuan in Series A+ Financing, Aims to Ship Over 100K Units of New AI Glasses in One Year | Exclusive Report by Yingke – 36Kr

    Sharge Technology Secures Nearly 100M Yuan in Series A+ to Launch Over 100,000 AI Glasses Within a Year

    New technology trialled on £2m Bedford Lock upgrade – BBC

    Revolutionary Technology Breathes New Life into £2 Million Bedford Lock Upgrade

    Tool Developed at Montana State Aims to Help Farmers Implement New Technologies – Northern Ag Network

    Montana State Unveils Innovative Tool That Empowers Farmers to Harness Cutting-Edge Technologies

    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    [News] Japan Develops 10nm Nanoimprint Technology, with Potential to Tackle EUV Bottleneck – TrendForce

    Japan Unveils Revolutionary 10nm Nanoimprint Technology Set to Surpass EUV Constraints

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

    Movies and TV shows casting across the US – Wyoming News Now

    Movies and TV shows casting across the US – Wyoming News Now

    Holiday light displays, ice hockey and more things to do this week: Around Baton Rouge – The Advocate

    Brighten Your Week in Baton Rouge: Holiday Light Displays, Ice Hockey, and More Exciting Events

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Sharge Technology Secures Nearly 100M Yuan in Series A+ Financing, Aims to Ship Over 100K Units of New AI Glasses in One Year | Exclusive Report by Yingke – 36Kr

    Sharge Technology Secures Nearly 100M Yuan in Series A+ to Launch Over 100,000 AI Glasses Within a Year

    New technology trialled on £2m Bedford Lock upgrade – BBC

    Revolutionary Technology Breathes New Life into £2 Million Bedford Lock Upgrade

    Tool Developed at Montana State Aims to Help Farmers Implement New Technologies – Northern Ag Network

    Montana State Unveils Innovative Tool That Empowers Farmers to Harness Cutting-Edge Technologies

    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    [News] Japan Develops 10nm Nanoimprint Technology, with Potential to Tackle EUV Bottleneck – TrendForce

    Japan Unveils Revolutionary 10nm Nanoimprint Technology Set to Surpass EUV Constraints

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home General

384,000 sites pull code from sketchy code library recently bought by Chinese firm

July 4, 2024
in General
384,000 sites pull code from sketchy code library recently bought by Chinese firm
Share on FacebookShare on Twitter

The supply-chain threat that won’t die —

Many website admins, it seems, have yet to get memo to remove Polyfill[.]io links.

Dan Goodin
– Jul 3, 2024 7:36 pm UTC

384,000 sites pull code from sketchy code library recently bought by Chinese firm

Getty Images

More than 384,000 websites are linking to a site that was caught last week performing a supply-chain attack that redirected visitors to malicious sites, researchers said.

For years, the JavaScript code, hosted at polyfill[.]com, was a legitimate open source project that allowed older browsers to handle advanced functions that weren’t natively supported. By linking to cdn.polyfill[.]io, websites could ensure that devices using legacy browsers could render content in newer formats. The free service was popular among websites because all they had to do was embed the link in their sites. The code hosted on the polyfill site did the rest.

The power of supply-chain attacks

In February, China-based company Funnull acquired the domain and the GitHub account that hosted the JavaScript code. On June 25, researchers from security firm Sansec reported that code hosted on the polyfill domain had been changed to redirect users to adult- and gambling-themed websites. The code was deliberately designed to mask the redirections by performing them only at certain times of the day and only against visitors who met specific criteria.

The revelation prompted industry-wide calls to take action. Two days after the Sansec report was published, domain registrar Namecheap suspended the domain, a move that effectively prevented the malicious code from running on visitor devices. Even then, content delivery networks such as Cloudflare began automatically replacing pollyfill links with domains leading to safe mirror sites. Google blocked ads for sites embedding the Polyfill[.]io domain. The website blocker uBlock Origin added the domain to its filter list. And Andrew Betts, the original creator of Polyfill.io, urged website owners to remove links to the library immediately.

As of Tuesday, exactly one week after malicious behavior came to light, 384,773 sites continued to link to the site, according to researchers from security firm Censys. Some of the sites were associated with mainstream companies including Hulu, Mercedes-Benz, and Warner Bros. and the federal government. The findings underscore the power of supply-chain attacks, which can spread malware to thousands or millions of people simply by infecting a common source they all rely on.

“Since the domain was suspended, the supply-chain attack has been halted,” Aidan Holland, a member of the Censys Research Team, wrote in an email. “However, if the domain was to be un-suspended or transferred, it could resume its malicious behavior. My hope is that NameCheap properly locked down the domain and would prevent this from occurring.”

What’s more, the Internet scan performed by Censys found more than 1.6 million sites linking to one or more domains that were registered by the same entity that owns polyfill[.]io. At least one of the sites, bootcss[.]com, was observed in June 2023 performing malicious actions similar to those of polyfill. That domain, and three others—bootcdn[.]net, staticfile[.]net, and staticfile[.]org—were also found to have leaked a user’s authentication key for accessing a programming interface provided by Cloudflare.

Censys researchers wrote:

So far, this domain (bootcss.com) is the only one showing any signs of potential malice. The nature of the other associated endpoints remains unknown, and we avoid speculation. However, it wouldn’t be entirely unreasonable to consider the possibility that the same malicious actor responsible for the polyfill.io attack might exploit these other domains for similar activities in the future.

Of the 384,773 sites still linking to polyfill[.]com, 237,700, or almost 62 percent, were located inside Germany-based web host Hetzner.

Censys found that various mainstream sites—both in the public and private sectors—were among those linking to polyfill. They included:

Warner Bros. (www.warnerbros.com)
Hulu (www.hulu.com)
Mercedes-Benz (shop.mercedes-benz.com)
Pearson (digital-library-qa.pearson.com, digital-library-stg.pearson.com)
ns-static-assets.s3.amazonaws.com

The amazonaws.com address was the most common domain associated with sites still linking to the polyfill site, an indication of widespread usage among users of Amazon’s S3 static website hosting.

Censys also found 182 domains ending in .gov, meaning they are affiliated with a government entity. One such domain—feedthefuture[.]gov—is affiliated with the US federal government. A breakdown of the top 50 affected sites is here.

Attempts to reach Funnull representatives for comment weren’t successful.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Ars Technica – https://arstechnica.com/?p=2035216

Previous Post

High-altitude cave used by Tibetan Buddhists yields a Denisovan fossil

Next Post

Norfund looking to invest close to $500m in SE Asia from climate fund

The art of solo travel: 8 destinations perfect for exploring alone (even as a woman) – VegOut

The Art of Solo Travel: 8 Perfect Destinations for Exploring on Your Own (Especially for Women)

December 28, 2025
Sharge Technology Secures Nearly 100M Yuan in Series A+ Financing, Aims to Ship Over 100K Units of New AI Glasses in One Year | Exclusive Report by Yingke – 36Kr

Sharge Technology Secures Nearly 100M Yuan in Series A+ to Launch Over 100,000 AI Glasses Within a Year

December 28, 2025
4 Takeaways From the Ravens’ Win Over the Packers – FOX Sports

4 Takeaways From the Ravens’ Win Over the Packers – FOX Sports

December 28, 2025
World Darts Championship: Jonny Clayton holds his nerve to reach last-16 – ESPN

Jonny Clayton Clutches Victory to Advance to World Darts Championship Last 16

December 28, 2025
Russia’s War Economy Falters as Civilian Industries Slide Into Deep Decline – UNITED24 Media

Russia’s War Economy Collapses as Civilian Industries Plunge Into Crisis

December 28, 2025
My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

My Favorite Reality Show of 2025 Had a Final Twist that Left Me Shook – PureWow

December 28, 2025
Letter to the editors: Mental health talk brings NIMBYs out in Moccasin Bend relocation – Chattanooga Times Free Press

Community Outcry Erupts Over Moccasin Bend Relocation Amid Mental Health Debate

December 28, 2025
Trump says US military struck ISIS terrorists in Nigeria – CNN

Trump says US military struck ISIS terrorists in Nigeria – CNN

December 28, 2025
Marxism and the Dialectics of Ecology – Monthly Review

Unveiling Marxism: Exploring the Dynamic Dialectics of Ecology

December 27, 2025
DHDC offers Free First Monday, Girls Who Science programs – Amarillo Globe-News

Discover Exciting Free Programs: Join DHDC’s First Monday and Girls Who Science Events!

December 27, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (991)
  • Economy (1,010)
  • Entertainment (21,887)
  • General (18,994)
  • Health (10,050)
  • Lifestyle (1,023)
  • News (22,149)
  • People (1,016)
  • Politics (1,024)
  • Science (16,225)
  • Sports (21,511)
  • Technology (15,993)
  • World (999)

Recent News

The art of solo travel: 8 destinations perfect for exploring alone (even as a woman) – VegOut

The Art of Solo Travel: 8 Perfect Destinations for Exploring on Your Own (Especially for Women)

December 28, 2025
Sharge Technology Secures Nearly 100M Yuan in Series A+ Financing, Aims to Ship Over 100K Units of New AI Glasses in One Year | Exclusive Report by Yingke – 36Kr

Sharge Technology Secures Nearly 100M Yuan in Series A+ to Launch Over 100,000 AI Glasses Within a Year

December 28, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version