Live data from Hacker News

Internet Archive: Security breach alert

theverge.com

21–30 of 648 posts

Re: Internet Archive: Security breach alert

#23

It looks like someone has compromised one of their subdomains for Polyfill Update: Subdomain seems to be returning normal responses again now.

You mean the IA included some JS polyfill from a subdomain and that's what's compromised / where the alert is coming from?

Re: Internet Archive: Security breach alert

#24
post #23

It looks like someone has compromised one of their subdomains for Polyfill Update: Subdomain seems to be returning normal responses again now.

You mean the IA included some JS polyfill from a subdomain and that's what's compromised / where the alert is coming from?

Yup.

https://news.ycombinator.com/item?id=41792651

Re: Internet Archive: Security breach alert

#25
post #23

It looks like someone has compromised one of their subdomains for Polyfill Update: Subdomain seems to be returning normal responses again now.

You mean the IA included some JS polyfill from a subdomain and that's what's compromised / where the alert is coming from?

Correct. The source subdomain of the popup seems to be hxxps[:]//polyfill[.]archive[.]org

Re: Internet Archive: Security breach alert

#26
post #23

It looks like someone has compromised one of their subdomains for Polyfill Update: Subdomain seems to be returning normal responses again now.

You mean the IA included some JS polyfill from a subdomain and that's what's compromised / where the alert is coming from?

yes, "https://polyfill.archive.org/v3/polyfill.min.js?features=fet..." is the URL with the malicious code
Post reply on HN