>Polyfill.io is used by academic library JSTOR as well as Intuit, World Economic Forum, and tons more.<p>> Since February, "this domain was caught injecting malware on mobile devices via any site that embeds cdn.polyfill.io,"<p>This kind of attack seems difficult to detect and ruthlessly effective. Imagine how much money they could've made by selling fake Davos tickets.