news.mlab.sh
Back to the feed
threat-intel

Suspicious Polyfill login prompts pop up on Toshiba, Muji websites

Medium
Summary

Toshiba and Muji websites were temporarily affected by malicious login prompts generated by the polyfill[.]io service, which injected malicious code into their scripts. The issue stemmed from the domain being acquired by a Chinese entity and subsequently reactivated, causing browsers to display fake login screens. Both companies have since resolved the issue and suspended the problematic service.

The incident began when the polyfill[.]io service, a JavaScript CDN used to support legacy browsers, was compromised. The domain was acquired by a Chinese entity, leading to the injection of malicious code into the CDN's scripts. This resulted in websites, including Toshiba and Muji, displaying deceptive login prompts to users attempting to access their accounts. While there's no evidence of compromised credentials being stolen at this time, the situation highlights the risks associated with relying on third-party CDNs and the potential for vulnerabilities to be exploited.

Read the full article at BleepingComputer