Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsCensys counted 384,773 internet-facing hosts whose HTTP responses still referenced cdn.polyfill.io or cdn.polyfill.com on July 2, 2024—five days after Namecheap suspended polyfill.io. Those were stale references, not proof that every host was still serving malicious code or had been compromised. The count shows why suspending a dangerous domain does not remove the script tags and other dependencies that websites already contain.
What Censys counted—and what it did not
The July 2, 2024 figure is a historical internet-observation snapshot from Censys, not a live count for 2026. Censys looked for specified strings in HTTP response bodies. A match indicates that a host exposed a reference; it does not establish that the referenced script loaded successfully, that malicious code ran for a visitor, or that the host was compromised.
| Censys observation | What it describes |
|---|---|
| 384,773 hosts | HTTP responses containing a reference to https://cdn.polyfill.io or https://cdn.polyfill.com on July 2, 2024. |
| About 237,700 hosts | Hosts in Hetzner’s AS24940 network, primarily in Germany, within the affected set Censys measured on July 2, 2024. |
| 182 hosts | Hosts displaying a .gov domain in the affected set on July 2, 2024. |
| 216,504 hosts | Hosts referencing either polyfill-fastly.io or cdnjs.cloudflare.com/polyfill by July 2, 2024, up from 80,312 on June 28, 2024. A reference alone does not show that a host was malicious. |
| 1,637,160 hosts | Combined hosts linking to one or more of four potentially associated domains: bootcdn.net, bootcss.com, staticfile.net and staticfile.org. |
These counts are not directly interchangeable with estimates from other organizations. SecurityWeek reported Censys’s findings alongside estimates from Sansec of 100,000 affected websites and Cloudflare’s estimate of “tens of millions.” The sources used different measurements; Censys’s figure is specifically a count of hosts with exposed HTTP references in its July 2 scan.
Why the Polyfill.io incident affected existing sites
Polyfill.js supplies browser features that newer browsers may have natively but older browsers lack. Sites that included it from a third-party CDN delegated delivery of that client-side code to the domain operator. Censys’s ARC Research Team reported on July 2, 2024 that Funnull, a Chinese CDN company, acquired the previously legitimate Polyfill.io domain and GitHub account in February 2024. Censys said the service later redirected visitors to malicious sites and deployed malware using evasion techniques.
#1 Best Overall
Because a site could keep the same script tag while the operator changed what the domain delivered, the risk was not limited to a deliberate update by the site owner. Namecheap suspended polyfill.io on June 27, 2024, mitigating the immediate threat from the live domain. Suspension did not edit websites’ source code, templates, stored content or generated pages, which is why Censys could still find references afterward.
Censys and SecurityWeek noted that high-profile domains among those connected to the incident included Warner Bros, Hulu, Mercedes-Benz, Pearson, JSTOR, Intuit and the World Economic Forum. The presence of a domain in a scan is evidence of a reference, not by itself evidence that the organization’s systems were breached.
Which related domains should site owners review?
Censys traced four active domains to the same leaked-account context: bootcdn.net, bootcss.com, staticfile.net and staticfile.org. It found that bootcss.com showed signs of similar malicious activity, with evidence dating to June 2023. Censys did not say the other three were malicious, so treat them as domains to investigate rather than confirmed threats.
Censys also observed six hosts presenting wildcard.polyfill.io.bsclink.cn on July 2, 2024, hosted in Singapore-based AS139057 infrastructure. The relationship between that observation and Funnull was unclear. Do not assume it proves common ownership or activity.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →The scan also counted references to polyfill-fastly.io and cdnjs.cloudflare.com/polyfill. Censys identified these as alternative endpoints, not as domains showing the same malicious activity. Their appearance in the count is not evidence that those references were malicious.
How to find Polyfill.io references on your site
Search the places that can produce or serve public pages, not just the main application source. A reference may live in a shared template, a CMS field or an already-built asset even after the original code has been removed.
Search code and content
- Check application repositories, shared layouts, templates, tag-manager configurations and CMS content for
polyfill.io,cdn.polyfill.ioandcdn.polyfill.com. - Search for the related domains Censys identified:
bootcdn.net,bootcss.com,staticfile.netandstaticfile.org. - Inspect lockfiles and dependency manifests to identify which package or integration introduced the library. Also check generated bundles and built HTML: a clean source tree does not guarantee the deployed output is clean.
- Review the HTML actually returned by the production site, including pages generated by a CMS or served through a CDN.
From a repository root, a basic text search with ripgrep is:
rg -n --hidden -g '!node_modules/**' -g '!.git/**' 'polyfill.io|polyfill-fastly.io|cdnjs.cloudflare.com/polyfill|bootcdn.net|bootcss.com|staticfile.(net|org)' .
This searches tracked and hidden text files while skipping Git metadata and the installed node_modules tree. It is a starting point, not a substitute for checking built assets, CMS-managed pages or production responses; binary files and external content may need separate review.
Rank #4
Search public HTTP responses with Censys
Censys’s July 8, 2024 release notes give this Censys Search query for Polyfill.io references:
services.http.response.body:{`https://cdn.polyfill.io`, `https://cdn.polyfill.com`}
For the four associated domains, Censys gives:
services.http.response.body:{`cdn.bootcdn.net`, `cdn.bootcss.com`, `cdn.staticfile.net`, `cdn.staticfile.org`}
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
- Comes with secure packaging
- It can be a gift item
- Easy to read text
Censys also describes ASM equivalents that search host and web-entity HTTP response bodies for the same strings. These searches help identify public responses visible to Censys; they do not inspect every private page, authenticated route, source repository or asset that may be served to users.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to remove the references and verify the fix
- Identify the source. Use the repository, CMS, asset and response searches to locate each reference. Trace dependencies to find whether a package, template, plugin or tag manager is reintroducing it.
- Remove the old call. Delete Polyfill.io references and investigate each related-domain match before deciding whether it is legitimate. Do not replace every matching string blindly if the same text appears in documentation or unrelated content.
- Choose and test a replacement. Confirm which browser features the site actually needs, then select a maintained source or self-host a reviewed library. Check the release, compatibility requirements and integrity controls before deploying it.
- Rebuild and deploy. Regenerate bundles and HTML from the corrected source. Purge or invalidate relevant CDN and application caches so visitors do not continue receiving old pages.
- Verify public output. Fetch representative production pages and inspect their HTML and scripts for the removed domains. Repeat the repository and asset searches against the deployed build.
- Monitor for recurrence. Add the strings to routine dependency and public-asset checks, and investigate any new match to determine whether a plugin, release process or content editor restored the reference.
What should replace cdn.polyfill.io?
Censys named Cloudflare’s cdnjs.cloudflare.com/polyfill and Fastly’s polyfill-fastly.io as alternatives in its 2024 coverage. That is not a guarantee about their current availability, governance or suitability for a particular site. Before switching, verify the endpoint and library version you intend to use, and confirm that the source is maintained and appropriate for your application.
| Approach | Control and trust | Compatibility and integrity | Operational trade-off |
|---|---|---|---|
| Third-party CDN endpoint | The provider serves the code, so changes and availability depend on that provider’s governance and operations. | Confirm the exact library version and required features. Whether version pinning, hashes or Subresource Integrity are supported depends on the endpoint and integration; verify rather than assume. | Can avoid hosting the file yourself, but the dependency remains an external runtime service. Monitor the public HTML and provider changes. |
| Self-hosted, reviewed library | Your organization controls the deployed copy and its release process, subject to how it obtains and reviews the upstream code. | Test browser coverage and features, pin the reviewed release in your build process, and use integrity checks where applicable. | Provides more direct control over the served asset but makes your team responsible for updates, deployment and compatibility testing. |
A replacement should be based on the features your site needs, not simply on preserving an old script URL. If current browsers already provide the required functionality, removing an unnecessary polyfill can reduce an external dependency altogether. If a library is still needed, establish who controls the delivered code, how updates are reviewed, and how your team will detect a changed or reintroduced dependency.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →

