Polyfill以外の怪しげなドメインについても国内で1万件以上ヒットしてますね...
July 2: Polyfill .io Supply Chain Attack – Digging into the Web of Compromised Domains
https://t.co/Tf6N1FvprJ
❗️ Over 30 official Red Hat npm packages were compromised. How they got in:
- A Red Hat employee's GitHub account was compromised.
- Attackers pushed "orphan commits" (detached from branch history) straight in, bypassing code review with no pull request.
- Payload "Miasma" (Mini Shai-Hulud variant) steals GitHub/cloud/Vault/SSH/npm secrets. Rotate everything since June 1.
- The commits added a workflow (ci.yaml) + script (_index.js) that abused npm trusted publishing, requesting a real OIDC token to publish backdoored versions.