cdn.jsdelivr.cc - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned cdn.jsdelivr.cc and returned a suspicious verdict (score 27). The page resolved to 172.67.202.3 on Cloudflare, Inc. in US. The domain was registered 1959 days ago through NameCheap, Inc.. 1 domain and 1 IP were contacted. 19 malware samples communicate with this URL. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 27) · Confidence 36%
- Scanned URL:
https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js - Domain: cdn.jsdelivr.cc · IP: 172.67.202.3 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · text/javascript
- Registrar: NameCheap, Inc. · domain age 1959 days · created 2021-04-10
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Sep 29 05: · subject CN=jsdelivr.cc
- Scan tier: fast · observed 2026-08-21 13:02:26 UTC
Malware communicating with this URL (19)
These samples were observed contacting or being served from cdn.jsdelivr.cc. Each links to its full analysis.
- 6373287286d936149e5ad101bc2791025a83302e029d4c0aa0a01c18855f9c65 - referenced ·
6373287286d936149e5ad101bc279102· first seen 2026-08-21 - 2fead45b16e04d8b1a6aa780aa3934320f77e08777c66e7acacfb46710b853d1 - referenced ·
2fead45b16e04d8b1a6aa780aa393432· first seen 2026-08-21 - 54b42d5c52e78ee91dfc574d2893c0137f40a9d30bcd45c9bc48bd578729d337 - referenced ·
54b42d5c52e78ee91dfc574d2893c013· first seen 2026-08-20 - 73d8de459d4cb33e21e4a2a19a48aa88bbe70c30adc734c618376073b5fdeeb1 - referenced ·
73d8de459d4cb33e21e4a2a19a48aa88· first seen 2026-08-16 - 3cac416bd50b979aab6217f6f4706db990d2f144aabd57dd04897daa1d069842 - referenced ·
3cac416bd50b979aab6217f6f4706db9· first seen 2026-08-15 - 739b868893617e4dd7933b5c675e639d8bee7b831eb809a08bda12066e7f0a70 - referenced ·
739b868893617e4dd7933b5c675e639d· first seen 2026-08-15 - a0bc56af8068c80d9d2e6a49406306dce372a7bb7f36681dffa7daaa3c049aad - referenced ·
a0bc56af8068c80d9d2e6a49406306dc· first seen 2026-08-15 - e91f5086b4e979eb2118f62c0c3a31b9f9d7536c8f1c9833d099e114e57188af - referenced ·
e91f5086b4e979eb2118f62c0c3a31b9· first seen 2026-08-14 - e8b3ef2acec859e800be975218771e597e53e7faaed56a0a28c681db7f19a823 - referenced ·
e8b3ef2acec859e800be975218771e59· first seen 2026-08-14 - 0e937ba616f17e62e22905205b60448d9409f05bb9f285a524568ac1f9477fbd - referenced ·
0e937ba616f17e62e22905205b60448d· first seen 2026-08-14 - fe30309744256c3fe326e26c17b04bb8878827888af476c1bc6a51d5e5ac129f - referenced ·
fe30309744256c3fe326e26c17b04bb8· first seen 2026-08-14 - ba0deb07124b42384feda3903763821b308ba8191af10b2afa7105404893c9e2 - referenced ·
ba0deb07124b42384feda3903763821b· first seen 2026-08-14 - 9d6f6025435101f278a39a708032c613e461bd7a9e8f60f375dd528c07b4f57d - referenced ·
9d6f6025435101f278a39a708032c613· first seen 2026-08-13 - 13337e01fae8fbc8be3d910de62978f65f08cea5cc0884cc2a9cf40c25a075ac - referenced ·
13337e01fae8fbc8be3d910de62978f6· first seen 2026-08-13 - bf04a71ee520b069080f965192f436c1cdda7fd017fb0a4b581b255d3b8bd1ad - referenced ·
bf04a71ee520b069080f965192f436c1· first seen 2026-08-13
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (lazyload.min.js) is known suspicious in the corpus
- File download routed to the malware sandbox (lazyload.min.js)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.67.202.3 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- lazyload.min.js ·
b219e4cd8f8f9216f159285019be30d6
Observed indicators
- cdn.jsdelivr.cc
- 172.67.202.3
- https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js
Other scans of cdn.jsdelivr.cc (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious
- 24 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/sweetalert2@10.16.0/dist/sweetalert2.all.min.js - 24 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/js/bootstrap.min.js - 24 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/jquery@3.6.0/dist/jquery.min.js - 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/sweetalert2@10.16.0/dist/sweetalert2.all.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/js/bootstrap.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/jquery@3.6.0/dist/jquery.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/popper.js@1.16.1/dist/umd/popper.min.js - 23 Aug 2026 - suspicious
Questions about cdn.jsdelivr.cc
- Is cdn.jsdelivr.cc safe?
- No. MalwareAnalyzer scanned cdn.jsdelivr.cc on 21 Aug 2026 and returned a suspicious verdict with a score of 27 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with cdn.jsdelivr.cc?
- 19 analysed samples communicate with this URL.
- How was cdn.jsdelivr.cc checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of cdn.jsdelivr.cc
Scanned on MalwareAnalyzer by Cyble · Open interactive scan