Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

The polyfill[.]io CDN domain, compromised in early 2024 when acquired by Funnull CDN, a Chinese entity, reactivated in late May 2026 and began serving HTTP 401 responses that trigger browser-native credential prompts on any site still loading scripts from the domain. Confirmed affected sites include Toshiba, Muji, Samsung Smart TV portal, Zojirushi, and several Japanese consumer brands. The business risk is direct: users visiting these sites see authentic-looking browser login dialogs, creating a convincing credential-harvesting surface with no malicious code on the affected site itself, making detection and attribution difficult for both site owners and end users.

Author

Tech Jacks Solutions