logo

If you're using Polyfill.io code on your site – like 100,000+ are – remove it immediately

ID: 8b5b3f22-2ea4-5969-9ab0-7a25e7ad7326

STIX ID: report--8b5b3f22-2ea4-5969-9ab0-7a25e7ad7326

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-06-25

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Researchers report that the cdn.polyfill.io domain—recently sold to an entity called Funnull—is being used in a web supply‑chain attack to inject malicious, dynamically generated JavaScript into pages that load polyfills; over 100,000 sites are affected, with observed mobile redirects to fraudulent sites and other malware behaviors, prompting advisories to remove the domain and use trusted mirrors or CDNs as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.