logo

Cloudflare: We never authorized polyfill.io to use our name

ID: 30b3c41f-1fe9-5f89-a6b6-8b1e1f252447

STIX ID: report--30b3c41f-1fe9-5f89-a6b6-8b1e1f252447

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-06-27

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

Cloudflare warns that the polyfill.io domain was purchased by an entity called 'Funnull' and used to inject malicious JavaScript in a supply-chain attack affecting over 100,000 websites; Cloudflare is automatically rewriting polyfill.io links for proxied sites to a safe mirror, urges removal of polyfill.io from projects, and recommends using Cloudflare's cdnjs mirror as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.