If you're using Polyfill.io code on your site – remove it immediately
theregister.com
theregister.com
CDNs are used, because not using CDNs is made unnecessarily hard.
Want a local version locked copy? Select one of the dozen mutually incompatible package managers. Then select one of the dozen buggy and slow mutually incompatibile build systems. Then rewrite your app for CJS or ESM depending on the library, because ESM was made purposefully incompatible.
Want to use a CDN? Copy and paste this one line in your HTML.
But many assets (especially CSS) rely on relative files - and we have apparently collectively decided that directories or other bunches or files is somehow a totally different thing than a file and need fundamentaly different logic - so just using the CDN makes you not have to worry about this.
> Since February, "this domain was caught injecting malware on mobile devices via any site that embeds cdn.polyfill.io,"
This kind of attack seems difficult to detect and ruthlessly effective. Imagine how much money they could've made by selling fake Davos tickets.
Lots of discussion: https://news.ycombinator.com/item?id=40791829