ThreatPaper
Financial FraudSupply Chain AttackCritical

Polyfill.io: How a CDN Acquisition Backdoored Hundreds of Thousands of Sites

By Sethu Satheesh · 2 Sept 2026 · 19 min read

Threat Actor: Funnull Technology Inc. (OFAC-designated; DPRK link assessed) · Target: 384,773+ websites embedding cdn.polyfill.io, and their mobile visitors

Source: sansec.io


Executive Summary

There was no intrusion. In February 2024 a company called Funnull bought the polyfill.io domain and its GitHub repository, and from that moment every website with <script src="https://cdn.polyfill.io/..."> in its markup — several hundred thousand of them — was executing code chosen by the new owner.

That sentence is the entire attack. No credential was stolen, no build system compromised, no maintainer socially engineered. A domain changed hands in an ordinary commercial transaction, and with it the ability to run arbitrary JavaScript inside every visitor's browser on every site that trusted it.

Polyfill.io existed to solve a real problem. Built by Andrew Betts at Financial Times Labs in 2014, it served browser-compatibility shims tailored to each visitor's user agent, so developers could use modern JavaScript without worrying about old browsers. By 2017 it was handling requests from tens of millions of browsers a day. The Financial Times later transferred the project, and it eventually reached Funnull.

Betts, who had built the thing, saw the danger immediately. On 25 February 2024 he posted a public warning that anyone using it should remove it, noting that he had never owned the domain and had no influence over its sale, and adding the observation that made the whole dependency unnecessary: "No website today requires any of the polyfills in the polyfill.io library." The features it patched had long since shipped in every major browser. Cloudflare and Fastly stood up safe mirrors four days later.

The warnings were four months early and largely unheeded. On 24 June 2024 the domain began serving malware, and on 25 June Sansec published the analysis. The payload was built to be hard to catch: it fired only on mobile devices, only during certain hours, only for a randomised fraction of visitors, skipped anyone with an administrator cookie, and delayed execution when it detected a web analytics service watching. Those it selected were sent to a sports betting site via www.googie-anaiytics[.]com — a homoglyph of Google Analytics chosen so that a developer glancing at a network tab would read past it.

Namecheap suspended the domain on 27 June. Censys counted 384,773 affected hosts on 2 July.

Nearly a year later, on 29 May 2025, the US Treasury sanctioned Funnull Technology Inc. and its administrator Liu Lizhi — not for this attack, but as infrastructure for cryptocurrency investment fraud responsible for over $200 million in victim-reported US losses. Neither the Treasury press release nor the OFAC designation mentions polyfill.io. The company that backdoored several hundred thousand websites was sanctioned for something else entirely, which is either a coincidence or the clearest available evidence that the polyfill acquisition was one line item in a much larger criminal infrastructure business.

As of May 2026, more than 61,000 pages still embed the script.

Verification of Claims

Claim: Funnull acquired the polyfill.io domain and GitHub account in February 2024. → Verified — Sansec's June 2024 report states "In February this year, a Chinese company bought the domain and the Github account." Corroborated by the timeline of responses: Andrew Betts published his warning on 25 February 2024, and Cloudflare and Fastly launched replacement mirrors on 29 February 2024. Neither response is possible before the acquisition it reacted to.

Claim: The domain served malicious code redirecting visitors to gambling and adult sites. → Verified — Documented by Sansec on 25 June 2024 and independently by cside, Censys and multiple vendors. The redirect chain used the spoofed domain www.googie-anaiytics[.]com and directed mobile users to a sports betting destination.

Claim: The payload used deliberate anti-analysis measures. → Verified — Sansec documented desktop-device detection, administrator-cookie detection, delayed execution when a web analytics service was present, time-of-day activation windows, randomised probability thresholds, referrer checking and specific hostname targeting.

Claim: The attack affected 100,000 websites. → Unverified — 100,000 is the default result cap of PublicWWW, the code-search tool researchers used to count embeds, and every count derived from it landed at the cap. Independent measurement produced larger figures: Censys counted 384,773 affected hosts on 2 July 2024, and cside reported more than 490,000 after querying past the cap. The widely repeated figure describes a tool's pagination limit rather than the attack's reach.

Claim: Funnull purchased polyfill.io in July 2024. → False — The malicious behaviour was discovered on 24 June 2024 and the domain was suspended on 27 June 2024, both before July. The February 2024 date is established by Sansec's reporting and by the dated public responses of Andrew Betts and of Cloudflare and Fastly in the same month.

Claim: The United States sanctioned Funnull over the polyfill.io supply chain attack. → Unverified — Funnull Technology Inc. and Liu Lizhi were designated by OFAC on 29 May 2025, which is verified. However, the stated basis is infrastructure for "pig butchering" cryptocurrency investment scams causing over $200 million in US victim-reported losses. Neither the Treasury press release nor the SDN designation entry mentions polyfill.io, and this paper could locate no primary government document connecting the designation to the supply chain attack. The connection is drawn by researchers and journalists, and may well be correct; it is not stated by the designating authority.

Claim: North Korean actors were behind the polyfill.io attack. → Assessed, not confirmed — Hudson Rock reported analysis of data recovered from an infostealer-infected endpoint belonging to an operator, including credentials for the Funnull DNS management portal and the Polyfill Cloudflare tenant, and messages describing domain configuration changes at Polyfill, which it assesses links the operation to DPRK-aligned activity. This is a single vendor's assessment based on one compromised device. No government has attributed the incident, and OFAC's designation identifies Funnull's administrator as a Chinese national.

Claim: The affected sites have been remediated. → False — More than 61,000 pages still embedded polyfill.io as of 18 May 2026, roughly two years after the domain was suspended and the danger publicised.

Timeline

Date Actor Event Source
2014 Andrew Betts Builds polyfill.io at Financial Times Labs cside
2017 Andrew Betts Reports ~91 million browsers per day requesting the library Betts
~2023 Financial Times Transfers the project onward; it later reaches Funnull cside
2024-02 Funnull Acquires the polyfill.io domain and GitHub account Sansec
2024-02-25 Andrew Betts Publicly warns users to remove it: "No website today requires any of the polyfills" Betts
2024-02-29 Cloudflare, Fastly Launch safe mirrors of the library cside
2024-06-24 Funnull Malicious behaviour begins to be observed cside
2024-06-25 Sansec, cside Publish forensic analysis of the injected malware Sansec
2024-06-26 Cloudflare Begins automatically rewriting polyfill.io URLs on proxied sites to its own mirror; Google warns advertisers cside
2024-06-27 Namecheap Suspends the polyfill.io domain Namecheap
2024-07-02 Censys Counts 384,773 affected hosts Censys
2024-10 Silent Push Publishes "Unveiling Triad Nexus" on Funnull CDN's wider operations Silent Push
2025-05-29 OFAC Designates Funnull Technology Inc. and Liu Lizhi under E.O. 13694 as amended by E.O. 14144 Treasury
2025-05-29 FBI Publishes advisory on Funnull infrastructure: 548 CNAMEs linked to 332,000+ domains FBI
2026-05-18 61,593 pages still embed polyfill.io cside

Attack Anatomy

Initial Access — Purchase

The access vector was a commercial transaction. Funnull bought the domain and the GitHub account, and thereby acquired every trust relationship the previous owners had accumulated over a decade.

This is worth separating from every other incident in this archive. In the 3CX cascade an attacker compromised a build system. In Codecov they extracted a credential from a Docker layer. In event-stream they socially engineered a maintainer. Here they filled in a form and paid.

There is no security control that prevents this, because nothing was violated. The <script src> tag in a hundred thousand HTML documents is a standing instruction to execute whatever that hostname returns, forever, with no version pinning, no integrity check and no expiry. The domain's owner has always had this power. It simply changed hands.

Technique mapping (this paper's assessment): T1195.002 Compromise Software Supply Chain; T1584.001 Compromise Infrastructure: Domains.

The Dormant Period — Four Months of Warnings

The malware did not appear until June. Between February and June the domain served, as far as anyone reported, functioning polyfills.

The warnings during that window were clear and came from the people best placed to give them. Andrew Betts, the library's author, told users to remove it and explained that he had never owned the domain and had no say in its sale. Cloudflare and Fastly published safe mirrors within days. The technical argument was unanswerable: the browser features being polyfilled had shipped everywhere years earlier, so the dependency provided almost nothing while carrying total execution authority.

The four-month gap between acquisition and payload is itself instructive. Whether deliberate or incidental, it meant the security conversation had ended by the time the attack began.

Execution — Selective, Evasive Redirection

The injected code was engineered around not being caught, and the specific choices reveal an accurate model of who investigates JavaScript problems and how.

It fired only on mobile devices. Developers debug on desktops; a payload that never runs on a desktop is a payload most developers cannot reproduce.

It skipped visitors with an administrator cookie. The people most likely to notice something wrong with a site are the people who run it, and they were excluded by design.

It delayed execution when a web analytics service was detected, reducing the chance that a redirect would appear as an anomaly in the traffic reports someone actually reads.

It activated only during certain hours, and then only for a randomised fraction of eligible visitors, with referrer and hostname checks narrowing it further. A site owner receiving one complaint would test and find nothing.

Together these turn a mass-distribution attack into something that behaves, from any individual observer's point of view, like a rumour.

T1480 Execution Guardrails; T1027 Obfuscated Files or Information.

Command and Control — Homoglyph Infrastructure

Redirects were routed through www.googie-anaiytics[.]com. Read quickly, at the size a hostname appears in a browser developer console, it is "google-analytics.com" — googie for google, anaiytics for analytics, substituting i for l in both.

The choice targets the specific moment a developer scans a network waterfall for something out of place. A request to an analytics domain on a page that uses analytics is the least interesting line in the list.

Selected visitors were forwarded to a sports betting destination at w9.vty70[.]net.

T1036 Masquerading; T1204.001 User Execution: Malicious Link.

The Wider Operation — Infrastructure Laundering

The polyfill acquisition was not a standalone project. Silent Push's October 2024 research on Funnull CDN described a broad operation, and the FBI's May 2025 advisory quantified it: 548 unique Funnull CNAMEs linked to more than 332,000 unique domains.

OFAC's designation describes the business model directly — purchasing IP addresses in bulk, generating domains on them using domain generation algorithms, and selling that infrastructure with web design templates to criminals running investment fraud, phishing and illegal gambling operations.

Read against that, polyfill.io looks less like a hacking operation and more like an acquisition: buying a distribution channel with several hundred thousand existing installations, to feed traffic into an existing scam funnel.

Threat Actor Profile

This is the only paper in this archive's supply chain series where the perpetrating entity is named in a government designation.

Funnull Technology Inc. was added to OFAC's Specially Designated Nationals list on 29 May 2025 under Executive Order 13694 as amended by Executive Order 14144. The designation lists aliases including Fang Neng CDN (方能CDN), Funnull CDN, Funnull Inc and Funnull LLC; an address in Taguig City, Philippines, and a China nexus; a Philippines registration number; an organisation establishment date of 7 September 2021; and both Ethereum and Tron digital currency addresses. It carries the [CYBER3] programme tag.

Liu Lizhi, a Chinese national identified as an administrator of Funnull, was designated at the same time. Treasury states he maintained spreadsheets tracking employees' progress on tasks including assigning domain names to cybercriminals for virtual currency investment fraud, phishing and online gambling. (This paper names him because a government designation is a public official action. It does not reproduce the identity document number published in the SDN entry.)

Two qualifications matter.

First, the designation is not for this attack. Treasury's stated basis is pig-butchering infrastructure and over $200 million in US victim-reported losses. Neither the press release nor the SDN entry mentions polyfill.io. Whatever the investigators knew, the public instrument does not connect the two.

Second, the DPRK assessment is a single vendor's. Hudson Rock's analysis of an infostealer-infected operator endpoint recovered credentials for the Funnull DNS management portal and the Polyfill Cloudflare tenant, alongside messages describing configuration changes at Polyfill, and assesses a link to DPRK-aligned activity. That is unusually direct evidence — operator-side, not infrastructure-side — but it is one vendor, one device, and no government has endorsed it. It also sits awkwardly beside OFAC identifying the administrator as a Chinese national, which is not necessarily a contradiction, since infrastructure-as-a-service arrangements can serve customers of any nationality, but it is not a resolved picture either.

Technical Indicators

Defanged.

Malicious infrastructure
  cdn.polyfill[.]io                 compromised delivery domain (suspended 27 Jun 2024)
  www.googie-anaiytics[.]com        homoglyph C2 / redirect broker
  w9.vty70[.]net                    sports betting redirect destination
OFAC-designated entity (SDN, 29 May 2025)
  FUNNULL TECHNOLOGY INC
    aka Fang Neng CDN (方能CDN), Funnull CDN, Funnull Inc, Funnull LLC
    Taguig City, Philippines; China
    Established 7 Sep 2021 · Programme tag [CYBER3]
    Websites  funnull[.]io · funnull[.]com · funnull[.]app · funnull[.]buzz
    ETH       0xd5ED34b52AC4ab84d8FA8A231a3218bbF01Ed510
    TRX       TNmRfnSUXZoWWzxcDDbf95eGQYXt1mJDt8
  LIU LIZHI — Chinese national, administrator
Payload behaviour (activation conditions)
  Mobile devices only            desktop visitors excluded
  Administrator cookie absent    site operators excluded
  Analytics service absent       execution delayed when detected
  Time-of-day window             activation restricted to certain hours
  Randomised probability         only a fraction of eligible visitors
  Referrer and hostname checks   further narrowing
Detection guidance
  Markup       grep source and templates for polyfill.io / polyfill.min.js
  CSP          report-only policy will surface unexpected script origins
  SRI          any <script src> to a third party without integrity= is this risk
  Scale        FBI advisory: 548 Funnull CNAMEs → 332,000+ domains

This is the one incident in this series where a government acted, which makes the shape of that action worth reading carefully.

Sanctions. On 29 May 2025 OFAC designated Funnull Technology Inc. and Liu Lizhi under Executive Order 13694 as amended by Executive Order 14144. The action blocks their US property and interests and generally prohibits US persons from transacting with them. Digital currency addresses were included in the designation, which extends the practical effect to blockchain analytics and compliance screening.

The stated basis is not polyfill.io. Treasury's release describes infrastructure for cryptocurrency investment fraud — over $200 million in US victim-reported losses, average individual losses exceeding $150,000 — and states the action was taken in close coordination with the FBI. The word "polyfill" does not appear in the press release or in the SDN designation entry.

Law enforcement. The FBI published an advisory the same day covering infrastructure used to manage domains related to cryptocurrency investment fraud between October 2023 and April 2025, identifying 548 unique Funnull CNAMEs linked to more than 332,000 domains, and directing reporting to IC3.

No prosecution. No indictment or arrest has been publicly reported for the polyfill compromise specifically.

Registrar and platform response — where the attack was actually stopped. Namecheap suspended the domain on 27 June 2024, two days after publication. Cloudflare began automatically rewriting polyfill.io references on proxied sites to its own mirror, protecting sites whose owners took no action at all. Google warned advertisers whose landing pages were affected. Cloudflare and Fastly had published safe mirrors four months earlier.

The pattern is consistent with the rest of this series: the compromise was ended in days by a registrar and a CDN, and the government instrument arrived eleven months later, aimed at the broader criminal enterprise rather than at this incident.

Impact Assessment

The affected population was never agreed on. The widely circulated 100,000 figure is a search tool's result cap. Censys measured 384,773 hosts. cside reported over 490,000. That a four-to-five-fold discrepancy persisted through two years of coverage says something about how supply chain impact gets reported: the first number published becomes the number, regardless of how it was produced.

The victims were high-trust sites. Reporting identified affected embeds on banks, government sites, major publishers and well-known brands, with early named examples including JSTOR, Intuit and the World Economic Forum. A visitor's decision to trust a page is made about the site, not about the third-party scripts it loads.

Harm to end users was diffuse and largely unmeasured. The redirects sent mobile users to betting and adult destinations, which functioned as an entry point into the fraud funnel Funnull's wider infrastructure served. No public accounting exists of how many people were redirected or what they subsequently lost, and the payload's evasion design means most affected site owners would never have known.

Remediation has effectively stalled. More than 61,000 pages still embed polyfill.io two years on. Those pages are not currently serving malware, because the domain is suspended — but they contain a live instruction to execute whatever that hostname returns, and the value of a domain with 61,000 standing script tags is not zero. This is the most durable finding in the paper: unmaintained pages carry unmaintained trust indefinitely.

The class of risk is enormous and largely unexamined. Every <script src> pointing at a third-party host is the same arrangement: unlimited execution authority, revocable only by the host, granted in perpetuity by a line of HTML that a developer wrote once and never revisited.

Lessons and Defensive Recommendations

For Security Teams and SOC Analysts

Inventory third-party script origins across your estate and treat that inventory as an asset register. Most organisations cannot answer "which external hosts can execute JavaScript on our pages" without doing new work, and that question is the whole of this attack.

Deploy Content Security Policy in report-only mode first. It costs nothing to break and immediately produces the inventory above, including scripts added years ago by people who have left.

Watch for domain ownership changes on third-party dependencies. WHOIS and certificate transparency changes on a host you load code from are a security event, and they are monitorable.

Assume your own visibility is degraded. This payload specifically excluded administrators, skipped desktops, and paused when analytics were present. Absence of reports from your team is close to meaningless against a payload built to avoid exactly those people.

For Developers and Architects

Use Subresource Integrity on every third-party script. An integrity= hash means a changed file fails closed rather than executing. SRI alone would have neutralised this attack entirely for any site that used it.

Self-host where you can. The bandwidth argument for third-party CDNs largely evaporated when browsers partitioned their caches by origin; the cross-site caching benefit that justified shared CDNs no longer exists.

Audit dependencies for continued necessity, not just for vulnerabilities. Polyfill.io's own author pointed out that no site needed it any more. A dependency that has stopped providing value while retaining full execution authority is pure liability, and nothing in a vulnerability scanner will tell you that.

Treat a <script src> as a permanent grant of execution to whoever controls that hostname, indefinitely. That is precisely what it is.

For Registrars, CDNs and Platforms

Namecheap's suspension and Cloudflare's automatic URL rewriting ended this attack for most of the internet within seventy-two hours, including for site owners who never learned it happened. That capability is real and it worked; it is also concentrated in very few hands.

Domains with large numbers of inbound script references are critical infrastructure regardless of who owns them. A transfer of such a domain warrants scrutiny that ordinary transfers do not.

For Leadership and CISOs

An acquisition is an attack vector. No control in your programme addresses a supplier being bought by someone hostile, and the sale is nobody's fault and breaks no rule. The only defence is technical — integrity checking and reduced third-party surface — because there is no policy or contract that survives the counterparty changing.

Free infrastructure has an owner with an exit. A service with no revenue model is a service whose owner may eventually sell it, and what they are selling is access to you.

The government acted here, eleven months later, for different reasons. Sanctions disrupted a criminal enterprise; they did not remediate a single website. The organisations that stopped this were a registrar and a CDN, within days. Plan accordingly.

Sources

Original Incident Report →

Related Research

A stranger emailed an unpaid maintainer offering to take over a package he no longer used. Three months later it was stealing private keys from bitcoin wallets holding more than 100 BTC. Nobody was ever identified.

Supply Chain AttackCryptocurrency & Web3

A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.

Supply Chain AttackState-Sponsored

On August 20, 2026, attackers hijacked a prominent Rust ecosystem crate and pushed a malicious update to `arrayref@0.3.10`, a small array-conversion utility with approximately 245 million lifetime...

Supply Chain Attack