cdn.jsdelivr.cc - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned cdn.jsdelivr.cc and returned a suspicious verdict (score 27). The page resolved to 104.21.34.87 on Cloudflare, Inc. in US. The domain was registered 1960 days ago through NameCheap, Inc.. 1 domain and 1 IP were contacted. 36 malware samples communicate with this URL. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 27) · Confidence 36%
- Scanned URL:
https://cdn.jsdelivr.cc/npm/jquery@3.6.0/dist/jquery.min.js - Domain: cdn.jsdelivr.cc · IP: 104.21.34.87 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · text/javascript
- Registrar: NameCheap, Inc. · domain age 1960 days · created 2021-04-10
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Sep 29 05: · subject CN=jsdelivr.cc
- Scan tier: fast · observed 2026-08-23 06:52:26 UTC
Malware communicating with this URL (36)
These samples were observed contacting or being served from cdn.jsdelivr.cc. Each links to its full analysis.
- d08316ef6ae8454766789e69fa46a7f6d8cfe569b554e4fbd6dee23340760fc3 - referenced ·
d08316ef6ae8454766789e69fa46a7f6· first seen 2026-08-23 - ac8e58dfc64af6dc26fcbb5550ce9dfc2d2bea55f4fc1fbb4d7cd5aa9c1bc75d - referenced ·
ac8e58dfc64af6dc26fcbb5550ce9dfc· first seen 2026-08-23 - 89b22bb924e76ee242fbf21dd1ae753b5fa96b0242362ca7804389f993874db8 - referenced ·
89b22bb924e76ee242fbf21dd1ae753b· first seen 2026-08-23 - 6346d3c6b38dcc3b9b33369031a61507490bdc95a469f352accabd09e39e56d2 - referenced ·
6346d3c6b38dcc3b9b33369031a61507· first seen 2026-08-22 - 75224e3f248dafeeadc291b294325a634e0982bad88f3b7f0a4af06ceba19c8c - referenced ·
75224e3f248dafeeadc291b294325a63· first seen 2026-08-22 - 2ebf0dbdf84fe07db08daed5adb0ec57dac61b59ea1254028c1dc5ee6ad744ce - referenced ·
2ebf0dbdf84fe07db08daed5adb0ec57· first seen 2026-08-22 - a8014f423457233312fb2ad71266eba9a727909a859916859353eafe8c12a9d2 - referenced ·
a8014f423457233312fb2ad71266eba9· first seen 2026-08-22 - 9ee8a200a5626e37c1914939cd0e1b95e46156b6ae3e86a2af706e73a9312ff6 - referenced ·
9ee8a200a5626e37c1914939cd0e1b95· first seen 2026-08-22 - 9cce41dc501192631caf8b66cea14b3e3876f292ad9d94a2db64022f766d0919 - referenced ·
9cce41dc501192631caf8b66cea14b3e· first seen 2026-08-22 - 1887d81364a608663d411e3f827abf816614f63b3560bfb44fdae853a54e4c50 - referenced ·
1887d81364a608663d411e3f827abf81· first seen 2026-08-22 - 96dd7f3e654efc7d7fb637b83198f7a8483c0663883c6051f6c056a1ab02b2c9 - referenced ·
96dd7f3e654efc7d7fb637b83198f7a8· first seen 2026-08-22 - 4282ab33caae3e8ec751fb078cc245e4eb6bd1cfa73b8f52169a83d25a65d6df - referenced ·
4282ab33caae3e8ec751fb078cc245e4· first seen 2026-08-21 - f83ada020399dddcfc3f0716b83c3397f03c8836b6cddf631b03f6e69988968b - referenced ·
f83ada020399dddcfc3f0716b83c3397· first seen 2026-08-21 - 45dd7edf04577179e87f47377b659cc405d6880c126ee772a110dc97249daa42 - referenced ·
45dd7edf04577179e87f47377b659cc4· first seen 2026-08-21 - af308ff0e19f7abf4e36bb50b87c7b52af5662012b673e706a05ae2803b9fe7f - referenced ·
af308ff0e19f7abf4e36bb50b87c7b52· first seen 2026-08-21
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (jquery.min.js) is known suspicious in the corpus
- File download routed to the malware sandbox (jquery.min.js)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.21.34.87 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- jquery.min.js ·
ee11e902416a1d896f538103110337b3
Observed indicators
- cdn.jsdelivr.cc
- 104.21.34.87
- https://cdn.jsdelivr.cc/npm/jquery@3.6.0/dist/jquery.min.js
Other scans of cdn.jsdelivr.cc (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/sweetalert2@10.16.0/dist/sweetalert2.all.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/js/bootstrap.min.js - 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/popper.js@1.16.1/dist/umd/popper.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/sweetalert2@10.16.0/dist/sweetalert2.all.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/js/bootstrap.min.js - 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js
Questions about cdn.jsdelivr.cc
- Is cdn.jsdelivr.cc safe?
- No. MalwareAnalyzer scanned cdn.jsdelivr.cc on 23 Aug 2026 and returned a suspicious verdict with a score of 27 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with cdn.jsdelivr.cc?
- 36 analysed samples communicate with this URL.
- How was cdn.jsdelivr.cc checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of cdn.jsdelivr.cc
Scanned on MalwareAnalyzer by Cyble · Open interactive scan