Polyfill.io is a JavaScript library service used by sites across the Internet to support older browsers. A June 2024 report by eCommerce security vendor Sansec detailed a supply chain attack in which the new owner of polyfil.io allegedly injected malware on mobile devices via any site that embeds cdn.polyfill.io, potentially affecting over 100,000 sites.
While the B2C Commerce platform is not affected by this issue, websites built using custom implementations may be using affected polyfill libraries. The embedded CDN (eCDN) used for B2C Commerce now provides an alternative service to address the ongoing supply chain attack. To reduce the risk of your storefront loading malicious code, we strongly advise you remove any links to the polyfill{.}io domain by replacing them with an alternative service such as https://cdnjs.cloudflare.com/polyfill/.
Please take immediate action to safeguard your users and if you are unable to remove the polyfill.io libraries, please reach out to Commerce Cloud Support as outlined in How to engage Commerce Cloud Support via the Salesforce Help portal for assistance.
For reference, examples of URLs which have been serving the malicious code include:
https[:]//polyfill(.)io/v3/polyfill.min.js
https[:]//cdn(.)polyfill(.)io/v2/polyfill.min.js
https[:]//cdn(.)polyfill(.)io/v3/polyfill.min.js
https[:]//polyfill(.)io/v3/polyfill.js
https[:]//cdn(.)polyfill(.)io/v2/polyfill.js
https[:]//cdn(.)polyfill(.)io/v1/polyfill.min.js
https[:]//polyfill(.)io/v2/polyfill.min.js
https[:]//cdn(.)polyfill(.)io/v3/polyfill.js
https[:]//polyfill(.)io/v2/polyfill.js
002330975

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.