Polyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script
When Sansec disclosed in late June 2024 that the polyfill.io domain had been sold and its hosted script rewritten to inject mobile-only scam redirects, hundreds of thousands of embedded sites — WordPress themes among them — discovered they had inherited an implant, invisible to desktop QA by design. This account traces the Funnull acquisition chain, the conditional payload mechanics, Cloudflare's mirror intervention, the DNS-harassment retaliation, the 2025 arrests, and the inventory lesson every site owner still owes themselves.
