Polyfill.io in https://developer.blender.org/docs/ - Potential malware issue [RESOLVED: polyfill.io dependencies removed]

image

Seems my browser guard only blocks it in Blender Developer Documentation pages. Just wanted to warn anyone that uses the docs.


There has been a polyfill.io supply chain attack reported on June 25, 2024. A lot of eyes are on this attack and people are removing dependencies that use polyfill.

I recommend reading the article from Censys - July 2: Polyfill.io Supply Chain Attack – Digging into the Web of Compromised Domains

First direct block from the article:

  • On June 25, 2024, the Sansec forensics team published a report revealing a supply chain attack targeting the widely-used Polyfill.io JavaScript library. The attack originated in February 2024 when Funnull, a Chinese company, acquired the previously legitimate Polyfill.io domain and GitHub account. Shortly thereafter, the service began redirecting users to malicious sites and deploying sophisticated malware with advanced evasion techniques.

I removed links to non-blender websites in-case of an automatic topic removal. Easy enough to do a web-search about it.

3 Likes

Just to note, I was using firefox when I got this popup.

Thanks for the heads up, the topic has been brought to our IT/website team :slight_smile:

2 Likes

The polyfill.io dependency has been replaced with a safe mirror supplied by Cloudflare.

6 Likes