cdn.jsdelivr.cc - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned cdn.jsdelivr.cc and returned a suspicious verdict (score 27). The page resolved to 104.21.34.87 on Cloudflare, Inc. in US. The domain was registered 1961 days ago through NameCheap, Inc.. 1 domain and 1 IP were contacted. 40 malware samples communicate with this URL. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 27) · Confidence 36%
- Scanned URL:
https://cdn.jsdelivr.cc/npm/sweetalert2@10.16.0/dist/sweetalert2.all.min.js - Domain: cdn.jsdelivr.cc · IP: 104.21.34.87 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · text/javascript
- Registrar: NameCheap, Inc. · domain age 1961 days · created 2021-04-10
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Sep 29 05: · subject CN=jsdelivr.cc
- Scan tier: fast · observed 2026-08-23 19:37:30 UTC
Malware communicating with this URL (40)
These samples were observed contacting or being served from cdn.jsdelivr.cc. Each links to its full analysis.
- e2e99f0df1fc224a6a2d70fff24de19dde5b7f6c0e6e72d2c593620b8b3e66b6 - referenced ·
e2e99f0df1fc224a6a2d70fff24de19d· first seen 2026-08-23 - f3a05b3e6f07af7eeb7835c877cd2315dea9205fdd9557b894cef9c912af1bc3 - referenced ·
f3a05b3e6f07af7eeb7835c877cd2315· first seen 2026-08-23 - e7d2b28e5b5aef47c991faa579e0117981d49f8929007e084839c3d6c3b915b3 - referenced ·
e7d2b28e5b5aef47c991faa579e01179· first seen 2026-08-23 - 16f779bf0e84f83c74a64a366c4ba844ff0b2730893e0ad034b3af733cf85ac6 - referenced ·
16f779bf0e84f83c74a64a366c4ba844· first seen 2026-08-23 - d08316ef6ae8454766789e69fa46a7f6d8cfe569b554e4fbd6dee23340760fc3 - referenced ·
d08316ef6ae8454766789e69fa46a7f6· first seen 2026-08-23 - ac8e58dfc64af6dc26fcbb5550ce9dfc2d2bea55f4fc1fbb4d7cd5aa9c1bc75d - referenced ·
ac8e58dfc64af6dc26fcbb5550ce9dfc· first seen 2026-08-23 - 89b22bb924e76ee242fbf21dd1ae753b5fa96b0242362ca7804389f993874db8 - referenced ·
89b22bb924e76ee242fbf21dd1ae753b· first seen 2026-08-23 - 6346d3c6b38dcc3b9b33369031a61507490bdc95a469f352accabd09e39e56d2 - referenced ·
6346d3c6b38dcc3b9b33369031a61507· first seen 2026-08-22 - 75224e3f248dafeeadc291b294325a634e0982bad88f3b7f0a4af06ceba19c8c - referenced ·
75224e3f248dafeeadc291b294325a63· first seen 2026-08-22 - 2ebf0dbdf84fe07db08daed5adb0ec57dac61b59ea1254028c1dc5ee6ad744ce - referenced ·
2ebf0dbdf84fe07db08daed5adb0ec57· first seen 2026-08-22 - a8014f423457233312fb2ad71266eba9a727909a859916859353eafe8c12a9d2 - referenced ·
a8014f423457233312fb2ad71266eba9· first seen 2026-08-22 - 9ee8a200a5626e37c1914939cd0e1b95e46156b6ae3e86a2af706e73a9312ff6 - referenced ·
9ee8a200a5626e37c1914939cd0e1b95· first seen 2026-08-22 - 9cce41dc501192631caf8b66cea14b3e3876f292ad9d94a2db64022f766d0919 - referenced ·
9cce41dc501192631caf8b66cea14b3e· first seen 2026-08-22 - 1887d81364a608663d411e3f827abf816614f63b3560bfb44fdae853a54e4c50 - referenced ·
1887d81364a608663d411e3f827abf81· first seen 2026-08-22 - 96dd7f3e654efc7d7fb637b83198f7a8483c0663883c6051f6c056a1ab02b2c9 - referenced ·
96dd7f3e654efc7d7fb637b83198f7a8· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (sweetalert2.all.min.js) is known suspicious in the corpus
- File download routed to the malware sandbox (sweetalert2.all.min.js)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.21.34.87 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- sweetalert2.all.min.js ·
0b7274b0b5b7f411de46416a6c994106
Observed indicators
- cdn.jsdelivr.cc
- 104.21.34.87
- https://cdn.jsdelivr.cc/npm/sweetalert2@10.16.0/dist/sweetalert2.all.min.js
Other scans of cdn.jsdelivr.cc (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js - 24 Aug 2026 - suspicious
- 24 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/js/bootstrap.min.js - 24 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/jquery@3.6.0/dist/jquery.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/bootstrap@4.6.0/dist/js/bootstrap.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/jquery@3.6.0/dist/jquery.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/popper.js@1.16.1/dist/umd/popper.min.js - 23 Aug 2026 - suspicious ·
https://cdn.jsdelivr.cc/npm/lazyload@2.0.0-rc.2/lazyload.min.js - 23 Aug 2026 - suspicious
Questions about cdn.jsdelivr.cc
- Is cdn.jsdelivr.cc safe?
- No. MalwareAnalyzer scanned cdn.jsdelivr.cc on 23 Aug 2026 and returned a suspicious verdict with a score of 27 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with cdn.jsdelivr.cc?
- 40 analysed samples communicate with this URL.
- How was cdn.jsdelivr.cc checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of cdn.jsdelivr.cc
Scanned on MalwareAnalyzer by Cyble · Open interactive scan