The polyfill.io attack affected 100,000 websites
Assessment
The figure is a tool artifact. Researchers counting embeds used PublicWWW, a source-code search engine whose results are capped at 100,000 by default, so every count derived from it arrived at the cap and was reported as the measurement. The cap was the number. Independent measurement produced substantially larger figures. Censys, scanning directly rather than querying a search index, counted 384,773 affected hosts on 2 July 2024. cside, re-running the PublicWWW search past the default limit, reported more than 490,000 websites. Sansec's original report said "100K+", which is accurate as a floor. What propagated downstream was "100,000 websites" as a completed count, and it remained the standard figure in coverage for two years despite Censys publishing a number nearly four times larger within a week of disclosure. Rated Unverified rather than False because at least 100,000 sites were affected — the statement is not untrue, it is a lower bound presented as a measurement, and it understates the incident by a factor of four or five.
Where this claim appeared
Sonatype · 2024-06-27
https://www.sonatype.com/blog/polyfill.io-supply-chain-attack-hits-100000-websites-all-you-need-to-knowWhat “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
Polyfill.io: How a CDN Acquisition Backdoored Hundreds of Thousands of SitesThink this assessment is wrong? Report an error.