A supply chain compromise of the widely used Polyfill.io JavaScript service exposed a vast number of websites after the cdn.polyfill.io domain began serving malicious code to visitors. Reporting from BleepingComputer, The Hacker News, Censys, and Italy’s CERT-AgID said the incident initially affected more than 100,000 sites and was later tied to over 380,000 hosts, including major companies. The injected code redirected users to scam and fraudulent pages and created a risk of sensitive data theft, turning a trusted browser compatibility library into a large-scale web skimming and traffic hijacking vector.
CERT-AgID urged public administrations to immediately remove all Polyfill.io references from their sites, warning that the service could no longer be trusted even after Namecheap suspended and reclaimed the malicious domain. The agency said it had already taken mitigation steps for affected public-sector entities and was removing the plugin from its own exposed systems. Security researchers also advised organizations to audit dependencies, replace Polyfill.io with safer alternatives or self-hosted code, and verify that no lingering references to the compromised service remain in production environments.

Trace attribution and downstream blast radius.
9 events from the most recent confirmed update back to the earliest known activity.
Google researchers publicly attributed the Axios npm compromise to suspected North Korean actors, linking the activity to UNC1069 based on malware and infrastructure overlaps. Reporting said the campaign could have broad downstream impact because Axios is heavily used across cloud and development environments.
The malicious Axios package versions were taken down roughly three hours after publication, limiting but not eliminating downstream exposure. Wiz later reported seeing the malicious versions in about 3% of the environments it scanned.
Attackers allegedly compromised an Axios maintainer account and published at least two malicious Axios versions, 1.14.1 and 0.30.4, for Windows, macOS, and Linux. The packages introduced the malicious dependency plain-crypto-js to deliver credential-stealing malware and the WAVESHAPER.V2 backdoor.
By late March 2026, researchers referenced a separate major npm supply-chain attack that had been disclosed the previous week, indicating a broader wave of package ecosystem compromises beyond Axios. The provided references do not name the victim package in detail, but they establish this as a distinct earlier event.
Follow-on analysis found the Polyfill.io compromise had broader reach than initially reported, with Censys and later reporting tying the incident to hundreds of thousands of exposed hosts. One report cited impact on more than 380,000 hosts, including major companies.
CERT-AgID urged Italian public administrations to immediately remove Polyfill.io from their websites, update dependencies, and stop relying on the service because it was no longer available. It also said it had already taken mitigation actions for affected public-sector entities and was removing the plugin from its own exposed sites.
Following the abuse of cdn.polyfill.io, registrar Namecheap suspended and reclaimed the domain to stop further malicious script delivery from the compromised service.
Security reporting and CERT-AgID disclosed that the cdn.polyfill.io service had been compromised and was serving malicious JavaScript to websites that still referenced it. Early reporting said more than 100,000 sites were affected.
The Polyfill.io domain and service changed ownership earlier in 2024, a key precursor to the later supply-chain compromise because many websites continued loading JavaScript from the trusted domain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
techradar.com
Open sourcetheregister.com
Open sourceaxios.com
Open sourcethehackernews.com
Open sourcecensys.com
Open sourceagid.gov.it
Open sourcecert-agid.gov.it
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.