When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Blog post from Cloudflare
Cloudflare describes how its Page Shield machine-learning system identified eight malicious JavaScript payloads across four live e-commerce operations that public scanners largely had not classified as harmful. The campaigns included mobile- and time-gated affiliate-commission hijacking through intercepted clicks, clickless affiliate attribution theft via hidden iframes, a repurposed Lnkr malware script that collected telemetry and could remotely execute arbitrary JavaScript, and a highly selective mobile-ad cloaker that disabled analytics and customer support while attempting to replace advertising and tracking identifiers. These scripts used obfuscation, typosquatted delivery domains, browser-state checks, IP and geographic filtering, delayed execution, cooldowns, and conditional remote loading to evade one-time crawls and analyst inspection while leaving storefronts apparently functional. The detection system analyzes JavaScript as a graph of code relationships using a graph neural network, validates suspicious findings with an LLM, and uses an ensemble of frontier models and human review for difficult cases, feeding results back into model training. The report argues that continuous client-side monitoring and behavioral analysis are necessary because malicious code may only activate for particular visitors, devices, campaign sources, locations, or browsing conditions.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| LLM | 4 | 747 | 162 | 79 | -85% |
| Observability | 3 | 472 | 102 | 54 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.