Automatically replacing polyfill.io links with Cloudflare’s mirror for a safer Internet
ID: d32a1944-d286-57d7-bf44-41cfcbd97349
STIX ID: report--d32a1944-d286-57d7-bf44-41cfcbd97349
Feed Name: Cloudflare Blog
Cloudflare reports that the polyfill.io CDN was abused after a change in ownership to inject malicious JavaScript (notably loading domains like googie-anaiytics[.]com and kuurza[.]com) which, under certain conditions, redirected users to external betting sites. Cloudflare corroborated the activity with Page Shield telemetry, published IoCs and timestamps, and deployed an automatic HTML rewriting mitigation for proxied sites—replacing polyfill.io references with a safe cdnjs mirror—and recommends all site owners replace polyfill.io links immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
