Polyfill supply chain attack embeds malware in JavaScript CDN assets
On June 25, 2024, the Sansec security research and malware team announced that a popular JavaScript polyfill project had been taken over by a foreign actor identified as a Chinese-originated company.