This advisory serves to inform ORNA customers about a significant supply chain compromise involving the Polyfill.js library, which is widely utilized for ensuring website compatibility across various browsers. In February 2024, a supply chain attack was initiated following the acquisition of the domain polyfill.io and its associated GitHub repository by a Chinese company. Malicious code was injected into websites using the library, specifically targeting mobile users by redirecting them to fraudulent sites through a fake Google Analytics domain. The malware was designed to activate under specific conditions to evade detection by website administrators. The attack, referred to as Polykill, affected over 100,000 websites, including prominent users like JSTOR and the World Economic Forum. Due to the nature of the breach, security experts have advised against the continued use of Polyfill.js and suggested alternatives from providers such as Fastly and Cloudflare. Recommendations include blocking all requests to the compromised domain and removing Polyfill.js from tech stacks.