Skip to content

Bugfix/LI-97987 Swifter SDK Embeds Trojan CDN - Polyfill.io (Supply Chain Attack)#389

Merged
grmeyer-hw-dev merged 11 commits intomasterfrom
bugfix/LI-97987-replace-swifter
Jun 25, 2025
Merged

Bugfix/LI-97987 Swifter SDK Embeds Trojan CDN - Polyfill.io (Supply Chain Attack)#389
grmeyer-hw-dev merged 11 commits intomasterfrom
bugfix/LI-97987-replace-swifter

Conversation

@grmeyer-hw-dev
Copy link
Copy Markdown
Collaborator

Ticket: LI-97987

Sumarry

Swifter SDK Embeds Trojan CDN - Polyfill.io (Supply Chain Attack)
More detials here
Data Theorem

The App is using a 3rd Party SDK called "Swifter", which embeds staticfile.org (part of the polyfill.io CDN), a popular javascript hosting service that was compromised and is known to be serving malicious code.

Changes

  • Replace Swifter by envoy/Ambassador

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Jun 19, 2025

Dependency Review

✅ No vulnerabilities found.

Scanned Files

None

@grmeyer-hw-dev grmeyer-hw-dev changed the title Bugfix/li 97987 Swifter SDK Embeds Trojan CDN - Polyfill.io (Supply Chain Attack) Bugfix/LI-97987 Swifter SDK Embeds Trojan CDN - Polyfill.io (Supply Chain Attack) Jun 19, 2025
fzhang4-hw
fzhang4-hw previously approved these changes Jun 20, 2025
fzhang4-hw
fzhang4-hw previously approved these changes Jun 23, 2025
@grmeyer-hw-dev grmeyer-hw-dev merged commit 4376a39 into master Jun 25, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants