Malware

Compromised CDN

Compromised CDN is a public script or asset host that began serving malicious files, either because it was breached or because its domain changed hands. Every site that loads from it inherits the problem without touching a line of its own code.

How it is measured

List every `<script src>` and `<link href>` on a page that points off your own domain, then check each host's current ownership, certificate, and the content it returns. A file whose hash differs from the version you tested, or a library that suddenly contains an extra redirect, is the red flag.

Subresource Integrity is the direct measure. If a tag carries `integrity="sha384-..."` and the CDN serves something different, the browser refuses it and reports the failure.

Worked example

A marketing site loads `https://cdn.legacy-polyfills.example/polyfill.min.js` on 60 pages. The project's maintainer sold the domain, and the new owner serves the usual file plus a snippet that redirects mobile visitors to a fake prize page. Desktop testing shows nothing wrong.

The webmaster only finds it after a customer sends a phone screen recording. Replacing the tag with a self-hosted copy and deploying fixes all 60 pages in one commit.

How it differs

A compromised CDN is a trusted third party gone bad, and the harm arrives through a script you chose to include. Polyfill.io is the best-known example, where a domain sale led to injected redirects across many sites. A supply-chain attack is the wider category that also covers poisoned npm packages and build tools. A brand squat is not compromised at all; it is a fake host from the start.

Common errors

Assuming a big name host cannot go bad. Pinning a library version in the URL but not a hash. Forgetting abandoned `<script>` tags in old templates. Testing only from one desktop browser. Leaving a project-owned domain to expire so someone else registers it.

In practice

Count the external script hosts on your top five pages. Self-host what you can, add SRI hashes to what you cannot, and drop anything nobody remembers adding. Put the remaining hosts in your CSP so a swapped-in new host cannot load.

See also

Polyfill.io, Supply-chain attack

Sources

Count this on a real site.

Watch my website