Digging into the Web of Compromised Domains
ID: c819cd50-f21d-535e-a654-3d6499c3b347
STIX ID: report--c819cd50-f21d-535e-a654-3d6499c3b347
Feed Name: Censys Blog
Date Published: 2024-07-02
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
**Executive Summary:** On June 25–27, 2024 researchers disclosed a supply-chain attack in which the Polyfill.io CDN and GitHub account were acquired and used to serve malicious, evasive JavaScript that redirected users and deployed malware; Namecheap later suspended the malicious polyfill.io domain but Censys observed hundreds of thousands of hosts still referencing the compromised endpoints and identified four additional potentially-associated domains (bootcdn.net, bootcss.com, staticfile.net, staticfile.org), with evidence of active abuse and widespread exposure across major sites and hosting providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
