The new Chinese owner of the popular Polyfill JS project injects malware into more than 100 thousand sites
valaramech @ valaramech @fedia.io Posts 0Comments 30Joined 2 yr. ago

valaramech @ valaramech @fedia.io
Posts
0
Comments
30
Joined
2 yr. ago
In my experience, first-party JavaScript is more likely to be updated so rarely that bugs and exploits are more likely than supply chain attacks. If I heard about NPM getting attacked as often as I hear about CDNs getting attacked, I'd be more concerned.