PortSwigger / BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition
https://portswigger.net/burp/documentation/scanner/bchecks
GNU Lesser General Public License v3.0
617 stars 109 forks source link

Create a bcheck for detecting malicious Polyfill CDN #211

Closed KnugiHK closed 3 months ago

KnugiHK commented 3 months ago

The well-known Polyfill service CDN (polyfill.io) has been sold, and it is now serving malicious JavaScript code. Website owners using this CDN should remove the associated code from their sites immediately. For more information about this supply chain attack, visit https://sansec.io/research/polyfill-supply-chain-attack.

BCheck Contributions

KnugiHK commented 3 months ago

Thanks!

jmasters410 commented 3 months ago

Suggest adding domains from June 28th update on https://sansec.io/research/polyfill-supply-chain-attack to ensure detection on other domains.

PortSwiggerWiener commented 2 months ago

@jmasters410 Great idea. Fancy submitting a PR? :)

PortSwiggerWiener commented 2 months ago

@jmasters410 Here you go: https://github.com/PortSwigger/BChecks/blob/main/other/Javascript/malicious_javascript_imported.bcheck