Join Nostr
2026-09-16 21:05:48 UTC

oxhak on Nostr: Cloudflare says its Page Shield ML system detected four malicious operations ...

Cloudflare says its Page Shield ML system detected four malicious operations involving eight JavaScript payloads running on online storefronts. The campaigns hijacked affiliate commissions, intercepted shopper clicks, loaded remote code, altered analytics, or concealed activity from monitoring tools. Seven of the eight payloads were absent from VirusTotal, and URLScan issued no malicious verdict for any of them.

The system detected the scripts in live traffic by analyzing code structure and behavior, then used an LLM and human review to validate alerts. The campaigns used conditional execution based on factors such as device, time, browser state, referrer, host, and tracking parameters, allowing them to remain dormant during simple scans. Cloudflare’s findings show why continuous client-side visibility and behavioral analysis can expose attacks that reputation-based or one-time scanners miss.

https://blog.cloudflare.com/client-side-security-finds-4-malicious-campaigns/