Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
Toshiba and Muji warned visitors about suspicious login prompts on their sites that could collect credentials. Both said the screens came from an external Polyfill service.
Intelligence analysis by GPT-5.4 Mini

Japanese companies Toshiba and Muji reported unexpected sign-in screens on parts of their websites and told visitors not to enter credentials. The prompts were tied to polyfill[.]io, an external service already associated with malicious code in 2024.
It is like a store’s website suddenly showing a fake front desk that asks for a password. The companies said people should not type anything, because an old web helper made the fake screen appear.
Analysis
What happened
Toshiba and Muji each warned visitors that some pages on their websites could display a suspicious login screen. Both companies told users not to type anything into the prompt and, if they had already entered account details, to change their passwords.
Why the prompt appeared
According to the article, the screens were generated by the external service hosted at polyfill[.]io. That domain has a history: in 2024, malicious code was introduced through scripts delivered by its CDN. The article says some sites kept remnants of Polyfill code for years, even after the service was deactivated.
Security researcher Pasquale Pillitteri said the polyfill[.]io domain became active again in late May 2026 and began returning HTTP 401 authentication requests. Browsers can interpret that behavior as a request for credentials, which causes a username-and-password dialog to appear on affected pages.
Current status
Toshiba said it was working to remove the screen and advised users to cancel if they saw it. Muji said it had not confirmed unauthorized access or information leakage, but still asked customers to act cautiously. The article says both companies have solved the issue and suspended the service.
Broader impact
The report says other organizations, including Zojirushi, FiNC Technologies, Ishiyaku Publishers, and Hobonichi, may have been affected as well. The article also notes reports that Samsung Smart TVs and websites showed a login prompt on June 1. At this stage, there is no indication in the article that the affected sites were hacked or that entered credentials were stolen, but the incident shows how a third-party component can create a convincing phishing-style risk.
Key points
- Toshiba and Muji warned that suspicious login screens appeared on parts of their websites.
- The prompts were linked to the external service hosted at polyfill[.]io.
- Both companies told visitors not to enter information and to change passwords if they had already done so.
- The article says there is no indication that the affected websites were hacked or that credentials were stolen.
- Other Japanese sites and even some Samsung pages may have been affected by the same issue.
The companies say they have solved the issue and suspended the service, which should reduce exposure for visitors. If site owners remove leftover Polyfill code, the prompts should stop appearing on additional pages.
Users who already typed credentials into the prompt may have exposed their passwords and need to reset them. The article also says some sites kept old Polyfill code around, so similar prompts could keep appearing elsewhere until cleanup is complete.



