Skip to content

Polyfill as an example of Supply Chain attack #812

@LLoyderino

Description

@LLoyderino

Hi there,

I was thinking, for the next edition of the OWASP (2025?) a good example of Supply Chain attack could be the polyfill.io incident.

It's a good example of why not to trust 3rd party CDNs, especially considering how widespread it got, affecting over 100k websites across the world.
And it was the result of a popular domain expiring and being acquired by a malicious party.

A good place to place this would be in the "Software and Data Integrity Failures" chapter, probably together with (or in lieu of) the SolarWinds Orion attack:

around 100 or so were affected. This is one of the most far-reaching and
most significant breaches of this nature in history.

Metadata

Metadata

Assignees

No one assigned

    Labels

    2021Relates to 202 T10

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions