Skip to content
North Korean-Linked Polyfill Supply Chain Attack Affects 100,000 Websites

North Korean-Linked Polyfill Supply Chain Attack Affects 100,000 Websites

First seen 12 Mar 2026, 11:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 15, 2026 at 09:31 UTC
  • Approximately 100,000 websites affected by a supply chain attack linked to North Korea.
  • Attack initially attributed to China but later reassessed due to new evidence.
  • Exploitation of polyfill libraries allowed for injection of malicious code.

A significant supply chain attack has been linked to North Korean actors, impacting approximately 100,000 websites. Initially attributed to China, the incident was re-evaluated following the discovery of an infostealer infection. The attack exploited vulnerabilities in polyfill libraries, allowing attackers to inject malicious code into affected sites. The scope of the impact is extensive, with numerous organizations and users potentially exposed to data theft and further exploitation. The attack vector utilized compromised libraries that are widely used in web development. Security teams are currently assessing the damage and implementing measures to mitigate further risks. Ongoing investigations are focusing on the specific tools and methods employed by the attackers. As of now, remediation efforts are underway, but the full extent of the breach is still being determined.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 179d ago How this analysis works

Timeline

2024-01-15
Initial reports of the supply chain attack emerge.
2024-02-20
Attack attributed to Chinese actors based on early analysis.
2026-03-12
New evidence links the attack to North Korean involvement.

More articles in this cluster (1)