The domain netdna-ssl.com — formerly the asset CDN behind MaxCDN and WP Engine's Legacy Network — expired and was re-registered in July 2025 by an unrelated ad operator. The new owner controls wildcard DNS for *.wpengine.netdna-ssl.com, meaning thousands of sites still referencing legacy asset URLs now point to infrastructure outside WP Engine's control. A GitHub code search reveals nearly 4,000 files with references, including projects from Mozilla, Kong, and Nextcloud. The domain ranks in the global top 20,000, confirming real live traffic. Currently the attack is dormant because the Cloudflare cert doesn't cover the deep asset subdomains — but issuing a wildcard cert would instantly enable arbitrary JavaScript execution across all affected pages. The situation mirrors the polyfill.io supply chain attack of June 2024. Recommended mitigations include auditing and removing references to the domain, applying Subresource Integrity to third-party scripts, and deploying a strict Content Security Policy with reporting.

5m read timeFrom scotthelme.ghost.io
Post cover image
Table of contents
What netdna-ssl.com used to beWho owns it nowThe wildcardWhy it isn't on fire yetHow big is the blast radius?This isn't a forgotten backwater — it's a top 20,000 domainWe've seen this exact movie beforeWhat to actually do
2.2K Impressions