The polyfill.io CDN, embedded by more than 100,000 websites to deliver the Polyfill JavaScript library, was turned into a malware distribution channel after the domain and related GitHub account were reportedly acquired by a Chinese company. Researchers said the injected JavaScript selectively targeted visitors—especially mobile users—and redirected some of them to a sports betting site through spoofed analytics infrastructure. The malicious code also used anti-analysis techniques, including device checks, delayed execution, time-based activation, and logic to avoid triggering for administrators or when analytics tools were detected.
The incident prompted broad mitigation efforts across the ecosystem. Cloudflare introduced real-time rewrites for cdn.polyfill.io, Namecheap later placed the domain on hold and then took it down, and Google began warning advertisers and blocking Google Ads for eCommerce sites still loading the compromised service. Security firms advised organizations to remove all polyfill.io references from source code because modern browsers generally no longer require the library; where compatibility support is still needed, they recommended replacing it with safer alternatives from providers such as Cloudflare or Fastly.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
Google began blocking Google Ads for eCommerce sites whose landing pages still referenced polyfill.io, warning advertisers affected by the compromised service.
Cloudflare implemented real-time rewrites for cdn.polyfill.io requests to reduce immediate risk for affected sites still referencing the service.
Namecheap took down or placed the polyfill.io domain on hold, stopping further malware delivery from that domain. This also left websites still depending on the service with broken polyfill functionality.
Sansec disclosed the compromise of cdn.polyfill.io and described it as a supply-chain attack impacting over 100,000 sites. The report also documented anti-analysis behavior such as device checks, delayed execution, admin-user exclusion, and time-based activation.
After the acquisition, the polyfill.io service was turned into a malware delivery channel affecting more than 100,000 websites that embedded the library. The malicious code selectively targeted users, including mobile visitors, and redirected some of them to a sports betting site under specific conditions.
Sansec reported that a Chinese company acquired the cdn.polyfill.io domain and the associated GitHub account in February 2024, setting up the conditions for the later supply-chain attack.
Fastly published guidance announcing new options for websites using Polyfill.io, providing an alternative path for customers relying on the service. This represents an earlier vendor response related to Polyfill.io usage before the later June 2024 compromise disclosures and mitigations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
semgrep.dev
Open sourcecsirt.sk
Open sourcesansec.io
Open sourcecommunity.fastly.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.