Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

polyfill.io / bootcdn.net / bootcss.com / ... usages tracking #323379

Open
9 of 11 tasks
LeSuisse opened this issue Jun 29, 2024 · 0 comments
Open
9 of 11 tasks

polyfill.io / bootcdn.net / bootcss.com / ... usages tracking #323379

LeSuisse opened this issue Jun 29, 2024 · 0 comments
Assignees
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems

Comments

@LeSuisse
Copy link
Contributor

LeSuisse commented Jun 29, 2024

Description

On June 25 an ongoing supply chain attack via resources served by cdn.polyfill.io was exposed: https://sansec.io/research/polyfill-supply-chain-attack

Yesterday more domains used by the same actor have been identified.
Currently (2024-06-29), Namecheap has put on hold the polyfill.io domain but the other domains are still active.

Some usages of resources served by these domains have been spotted early by the nixpkgs community by looking at the content of their /nix/store:

In order to have a better cartography I checked the free/non broken/non insecure x86_64 packages we have in the cache for NixOS unstable b2852eb (thanks to delroth grep-nixos-cache tool 💚 ). I looked for the same domains currently blocked by uBlock Origin.

Raw results here: https://gist.github.com/LeSuisse/05b5e3f3bf72d43f4e433778dfab486b

Triage

I'm creating this issue to keep a public trace of the triaging work and remediation for impacted nixpkgs packages.

Impacted

Not Impacted

@LeSuisse LeSuisse added the 1.severity: security Issues which raise a security issue, or PRs that fix one label Jun 29, 2024
@LeSuisse LeSuisse self-assigned this Jun 29, 2024
@Sigmanificient Sigmanificient added the 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems label Jul 17, 2024
tomodachi94 added a commit to tomodachi94/nixpkgs that referenced this issue Oct 12, 2024
github-actions bot pushed a commit that referenced this issue Oct 14, 2024
yuanwang-wf pushed a commit to yuanwang-wf/nixpkgs that referenced this issue Oct 17, 2024
presto8 pushed a commit to presto8/nixpkgs that referenced this issue Oct 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 5. scope: tracking Long-lived issue tracking long-term fixes or multiple sub-problems
Projects
None yet
Development

No branches or pull requests

2 participants