A Chinese company has bought the popular Polyfill JS project and injected malware into over 100,000 sites that use the cdn.polyfill.io domain. The malware redirects mobile users to a sports betting site using a fake Google analytics domain. The original polyfill author recommends not using Polyfill at all, as it is no longer needed by modern browsers. Fastly and Cloudflare have put up trustworthy alternatives for those who still need it.