Malware

Polyfill.io

Polyfill.io is a script service that served browser compatibility code from cdn.polyfill.io. After the domain changed hands in 2024 it began returning injected code to some visitors, and sites that never changed a line were affected.

How it is measured

Check your own pages for any reference to the host: search HTML, templates, CMS script settings, and tag-manager containers for 'polyfill.io'. A crawl of rendered pages catches ones added by plugins. A polyfill file loaded from a different origin, such as a vendor mirror, is a separate question.

Tarsier lists the host in the Tarsier Threat Index, so Hack Check flags a page that still loads it. Outside Hack Check, remember the response could vary by user agent and referrer, so a plain fetch from a server may look clean.

Worked example

A regional hotel group's booking site has a footer tag pointing at cdn.polyfill.io/v3/polyfill.min.js. A contractor added it in 2019, and it is on 2,100 pages. In June 2024 an audit finds the host, and a fetch with a mobile user agent and a search referrer shows redirect code to a gambling site.

The group deletes the tag, since modern browsers need none of those features, then checks the CMS for other copies. Three microsites built from the same template still carry it.

How it differs

A compromised CDN is the general case: a host you trust starts serving something else. Polyfill.io is the named case where the domain was sold and then used to serve code, not a breach of the original operator. The defensive step is the same, but this incident has a name that scanners, blocklists, and advisories search for.

Common errors

Assuming a script tag you added years ago is still trustworthy. Testing with a desktop browser only, when the code targeted mobile visitors. Replacing the host with another unversioned URL. Missing copies inside tag managers, page-builder blocks, and old landing pages. Skipping staging and microsites in the re-scan.

In practice

Remove the tag. Most sites no longer need polyfills; if you do, self-host a pinned copy or use a mirror and pin it with Subresource Integrity. Re-scan rendered pages afterward, including microsites and staging, to confirm nothing still requests the host.

See also

Compromised CDN, Tarsier Threat Index

Sources

Count this on a real site.

Watch my website