---
title: "Pharos Response to Polyfill.io Malicious Code (CVE-2024-38526)"
slug: "polyfillio-supply-chain-attack"
updated: 2024-09-17T13:40:39Z
published: 2024-09-17T13:40:39Z
canonical: "kb.pharos.com/polyfillio-supply-chain-attack"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.pharos.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Pharos Response to Polyfill.io Malicious Code (CVE-2024-38526)

**Pharos Impact: None**

Pharos has reviewed all our software, 3rd party tools/libraries, internal infrastructure and cloud infrastructure and can confirm that we do not use the polyfill.io JavaScript library anywhere.

**Background**

Recently, a security exploit was discovered inside a popular open-source library that helps older browsers support newer functionality ([CVE-2024-38526](https://nvd.nist.gov/vuln/detail/CVE-2024-38526)).

[Polyfill.io Supply Chain Attack | Qualys Security Blog](https://blog.qualys.com/vulnerabilities-threat-research/2024/06/28/polyfill-io-supply-chain-attack)

Many organizations, including Pharos customers, are urgently investigating where this tool is used and how to update/repair those instances.
