What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes, a site that loaded scripts from Polyfill.io, BootCDN, Bootcss, or Staticfile could have been exposed to unwanted redirects after those services became associated with malicious activity. Researchers linked the four services through information exposed from a Cloudflare account and attributed them to one operator. But “millions of sites” is not a verified count of sites that ran malicious code: published figures describe different things, including reported impact, estimated service use, and possible exposure.

What happened in the Polyfill.io incident?

Polyfill.io hosted JavaScript polyfills: code intended to add browser features when a visitor’s browser did not support them natively. A website embedding a remotely hosted script relied on the service to supply code at page-load time. That created a supply-chain dependency: the service operator could change what the site loaded without the site owner changing the site’s own code.

Cloudflare and CERT-FR reported that Funnull acquired the Polyfill.io domain in February 2024. In June, incident reports described modified code that could redirect some visitors to unwanted destinations. Reports characterized the behavior as conditional, including targeting mobile users under particular conditions or at particular times. Google warned advertisers about possible unwanted redirects from Polyfill.io, Bootcss.com, Bootcdn.net, and Staticfile.org. These reports establish a risk and observed behavior, not that every site or visitor received a redirect. Cloudflare’s June 26, 2024 account and the CERT-FR advisory describe the ownership change and response.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How were Polyfill.io, BootCDN, Bootcss, and Staticfile connected?

According to BleepingComputer’s June 28, 2024 report, researchers found a public GitHub repository associated with Polyfill.io that exposed Cloudflare credentials and zone information. Using the credentials, researchers queried active zones on the associated Cloudflare account. The returned domain records included Polyfill.io, BootCDN, Bootcss, and Staticfile.

This is an infrastructure-based research attribution: the services appeared under a common Cloudflare account, which led researchers to attribute them to one operator. It is not a court finding, nor does it establish the legal identity of a named individual. The same report said suspicious BootCSS code had been discussed by developers in Chinese-language forums as early as June 2023. That suggests related activity may have predated the 2024 Polyfill.io disclosure, but it does not establish a precise campaign start date.

Was it really millions of affected sites?

There is no established exact combined count of sites that executed malicious code across the four services. The figures reported in June 2024 refer to different measures and should not be treated as interchangeable.

Figure What it describes What it does not establish
“Over 100,000 sites” BleepingComputer’s June 25, 2024 headline and opening impact statement about the Polyfill.io incident. A final verified count of sites where malicious code executed. Source.
“100,000 to tens of millions of websites” BleepingComputer’s June 28, 2024 range for the uncertain potential exposure across the wider, multi-CDN attack. A count of confirmed infections, redirects, or successful executions. Source.
“Tens of millions of websites (4% of the web)” An estimate of Polyfill.io use attributed to Cloudflare co-founder and CEO Matthew Prince in BleepingComputer’s June 28 report. A count of confirmed malicious executions or redirects. Source.

In other words, a large estimated audience or potential reach is not the same as proof that every site loaded malicious code—or that every visitor to a site was redirected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Could your site have been exposed?

A site could have been exposed if one of its pages loaded code from an affected service during the relevant period. The reference might be in a shared template or dependency rather than an individual page, so checking only a homepage is not enough. A reference is evidence of a dependency to investigate; by itself, it does not prove that a visitor received malicious behavior.

Rank #3
Sale
MOSA BEAR Password Keeper Book with Alphabetical Tabs,4.3"x5.7" Small Password Books for Seniors Password Notebook for Internet Website Address Log in Detail(Dark Blue)
  • 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
  • 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
  • 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
  • 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
  • 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.

Search code and deployed pages

  1. Search source repositories, templates, dependency files, build configuration, and generated pages for polyfill.io, bootcdn.net, bootcss.com, and staticfile.org. Also search for the affected hostnames wherever they appear in script URLs, since references may be assembled indirectly.
  2. Inspect the rendered HTML and browser network requests for production pages, including pages built from shared components or served by a content-management system. A clean source search alone may miss injected markup or references added during deployment.
  3. Review third-party scripts and the site itself for suspicious code additions, unexpected outbound requests, or redirect behavior. The reported behavior was conditional, so the absence of a redirect in a single visit does not establish that a reference was safe.

Semgrep documented an incident-specific code-search rule for finding Polyfill.io references. Automated scanning can help, but manual searches remain useful, especially for generated output and systems outside a scanner’s repository coverage. Semgrep’s July 2, 2024 update described code search as then in beta and available to customers hosting code on GitHub.com; that dated description should not be taken as a statement of current availability.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should site owners replace or change?

Remove the affected remote reference

Remove Polyfill.io references rather than continuing to depend on the domain. Cloudflare’s June 2024 guidance recommended its cdnjs mirror and described mapping requests to the corresponding version. Semgrep also identified Cloudflare’s alternative and noted that Fastly had published an alternative. These are reported options, not an independent current comparison: check present availability, compatibility with the bundle and version your site needs, and the operational ownership of the resource before deploying a change.

Rank #4
AT-A-GLANCE Undated Website Address Book and Password Keeper, Black, 3.63 x 6.13 x .21 Inches (80-500-05)
  • Bookbound planner helps you keep track of passwords and favorite websites
  • Room for over 200 entries; 3.5 x 6 inch page sizes
  • User name and security questions field
  • Tips for what makes a strong password; web resources; notes pages
  • Printed on quality paper containing 30% post-consumer waste; black simulated leather cover; 3.63 x 6.13 x .21 inches

Do not assume a mirror is automatically a like-for-like replacement. Check which polyfills the site actually needs, whether the replacement serves the expected files and versions, and whether its host fits the site’s security policy. The original service creator Andrew Betts, quoted by Semgrep, argued that contemporary websites generally no longer require polyfills from the library; treat that as his assessment, not a universal guarantee about every site’s browser requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Strengthen controls around third-party code

  • Use Subresource Integrity (SRI) where suitable so a browser can verify that a fetched script matches an expected hash. SRI is less convenient for resources that are expected to change, so pinning and update procedures matter.
  • Use a Content Security Policy (CSP) to limit which origins can supply scripts. Allow only the hosts the site needs, and test policy changes to avoid breaking legitimate functionality.
  • Keep an inventory of external scripts, their owners, and why each is needed. Remove unused dependencies and review changes to the list as part of normal deployment.

CERT-FR explicitly recommends removing Polyfill.io references and strengthening third-party script controls, including SRI and CSP, in its July 11, 2024 advisory.

Understand the limits of automatic rewriting

Cloudflare said its automatic rewrite to a mirror was on by default for free-plan sites when its June 26, 2024 post was published, while paid-plan customers could enable it. That describes the feature at publication, not its present configuration or availability. Even where an edge rewrite is active, review and update the source reference: code may be served through other paths, and source-level cleanup leaves a clearer, auditable dependency.

How did the response unfold?

  • February 2024: Cloudflare and CERT-FR reported Funnull’s acquisition of Polyfill.io. Cloudflare said it created a mirror in response to the ownership change and supply-chain concern.
  • June 2023, reported retrospectively: BleepingComputer said developers had discussed anomalous, obfuscated BootCSS code in Chinese-language forums. This is an early reported observation, not a definitive campaign start date.
  • June 25–26, 2024: Sansec’s warning and news coverage brought reported Polyfill.io redirects to wider attention. Cloudflare published its automatic rewriting measure and recommended replacing references.
  • June 26, 2024: CERT-FR reported that Namecheap had suspended Polyfill.io, making the domain and subdomains inaccessible at that time. This was a status report for that date, not a guarantee of present domain status.
  • June 28, 2024: BleepingComputer reported the researchers’ linkage of Polyfill.io, BootCDN, Bootcss, and Staticfile through exposed Cloudflare account information.
  • July 11, 2024: CERT-FR published its advisory recommending removal of Polyfill.io and stronger controls for third-party scripts.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.