Rogue Polyfill JavaScript CDN triggers suspicious login prompts on Toshiba, Muji websites
Toshiba and Muji alerted users to suspicious login prompts originating from polyfill.io, a third-party CDN service. This incident, linked to a 2024 episode where the polyfill.io domain fell into malicious hands and inserted problematic scripts, highlights the security vulnerabilities associated with third-party content delivery networks and external script dependencies. Users who encountered these prompts were advised to change their passwords, though there's no current indication of a hack or credential theft. The event serves as a critical reminder for website operators to audit and secure their CDN dependencies.
Key Takeaways
- Toshiba, Muji, and Zojirushi suspended the polyfill.io service after identifying unauthorized authentication pop-ups.
- The issue stems from a 2024 supply chain attack where the polyfill.io domain was sold to a Chinese entity and used to inject malicious scripts.
- Samsung Smart TVs and websites reportedly displayed identical 401-triggered login prompts on June 1, 2026.
- While no credential theft is confirmed, operators recommend that any users who entered data on these rogue screens change their passwords immediately.
Why It Matters
This resurgence of a known supply chain vulnerability underscores the extreme persistence of technical debt in modern web delivery. For streaming operators and tech giants, the incident demonstrates that even dormant or deactivated third-party dependencies can regain the ability to compromise client-side security if the underlying domain is reacquired or reactivated. This lapse highlights a failure in dependency auditing across disparate devices, from browsers to Smart TVs. Operators should watch for a rise in automated browser security policies that block unauthenticated third-party CDNs by default.
Additional Context
The polyfill.io crisis originally peaked in June 2024 when security researchers at Sansec discovered the domain was serving malicious JavaScript to over 100,000 websites. Per BleepingComputer in June 2024, the domain had been acquired by a Chinese entity named Funnull, which subsequently used the scripts to redirect mobile users to gambling and adult sites. The original creator of the Polyfill project, Andrew Betts, publicly urged developers to stop using the service immediately, noting that such CDNs represent a massive, unvetted trust vector in the web supply chain. In response to the 2024 incident, major industry players took aggressive defensive measures. Per Cloudflare and Google in June 2024, both companies launched safe, automated mirrors of the Polyfill library to prevent websites from loading scripts from the compromised cdn.polyfill.io domain. Despite registrar Namecheap suspending the domain at that time, many organizations failed to fully scrub the legacy code from their production environments. Recent reporting by security researcher Pasquale Pillitteri in June 2026 explains that the domain's registration transferred from Namecheap to GoDaddy in late May 2026. This transfer likely allowed the domain to begin responding to requests again, triggering the 401 authentication prompts seen on Japanese corporate sites and Samsung hardware. Security experts emphasize that modern browsers no longer require external polyfills for most features, making the continued presence of these scripts an unnecessary security risk.
Read full article at bleepingcomputer.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source