The recent large scale supply chain attack conducted via multiple CDNs, namely Polyfill.io, BootCDN, Bootcss, and Staticfile that affected up to tens of millions of websites has been traced to a common operator. Researchers discovered a public GitHub repository with leaked API keys helping them draw a conclusion.| BleepingComputer
The new Chinese owner of the popular Polyfill JS project injects malware into more than 100 thousand sites.| Sansec