logo

Automatically replacing polyfill.io links with Cloudflare’s mirror for a safer Internet

ID: d32a1944-d286-57d7-bf44-41cfcbd97349

STIX ID: report--d32a1944-d286-57d7-bf44-41cfcbd97349

Feed Name: Cloudflare Blog

Threat Score
80/100

Date Published: 2024-06-26

Date Updated: 2026-04-27

Author: Matthew Prince

...
...

Cloudflare reports that the polyfill.io CDN was abused after a change in ownership to inject malicious JavaScript (notably loading domains like googie-anaiytics[.]com and kuurza[.]com) which, under certain conditions, redirected users to external betting sites. Cloudflare corroborated the activity with Page Shield telemetry, published IoCs and timestamps, and deployed an automatic HTML rewriting mitigation for proxied sites—replacing polyfill.io references with a safe cdnjs mirror—and recommends all site owners replace polyfill.io links immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.