OFICIAL Cloudflare Blog

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

What happened
Based on Cloudflare Blog · Sep 16, 2026

Cloudflare’s Client-Side Security ML model detected eight live malicious JavaScript payloads on storefronts that evaded traditional scanners, exposing gaps in static detection methods.

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Cloudflare Blog — Cloudflare
Key points
·
Page Shield ML detected eight live malicious JavaScript payloads on storefronts that evaded VirusTotal and URLScan entirely.
·
One Lnkr payload remained unclassified on URLScan for over two years before Page Shield ML identified it executing live on a retailer’s storefront.
·
The GNN analyzes JavaScript as a syntax tree, catching threats that use obfuscation or dynamic loading without relying on known signatures.
Key numbers
·
3% of traffic) are sent to a large language model (LLM) on Workers AI for a secondary review.

Modern e-commerce storefronts can appear fully functional while hidden malicious JavaScript operates in the background, diverting affiliate revenue, hijacking analytics, or intercepting clicks without triggering visible errors. Traditional security tools often miss these threats because they rely on known signatures or static scans, leaving retailers unaware of unauthorized browser activity. Cloudflare’s Page Shield ML model was designed to identify such behavior by analyzing JavaScript behavior in real time, rather than waiting for a file to be labeled malicious.

In a review of four distinct operations uncovered by Page Shield ML, seven of the eight payloads were undetected by VirusTotal and URLScan, despite one payload remaining unclassified on URLScan for over two years. The model flagged all eight payloads in live traffic, demonstrating its ability to catch threats that evade conventional scanning tools. One payload, part of the Lnkr family, was found executing on a retailer’s storefront even though it had no prior malicious classification, highlighting the limitations of reactive security approaches.

The malicious scripts employed varied techniques to remain hidden, including conditional activation based on device, time, or referrer, and embedding affiliate requests within invisible iframes. Some scripts intercepted clicks, suppressed analytics tracking, or loaded additional malicious code dynamically, making them difficult to detect through single-point scans. Page Shield ML uses a graph neural network (GNN) to analyze JavaScript as a syntax tree, identifying suspicious patterns across obfuscation and minification without relying on known URLs or byte signatures.

To reduce false positives, scripts flagged by the GNN (less than 0.3% of traffic) are sent to a large language model (LLM) on Workers AI for a secondary review. Suspicious scripts are also analyzed by an ensemble of frontier models, which vote on classifications such as payment skimming, malware, or cryptomining. Human reviewers only examine scripts flagged as malicious or those lacking a clear majority vote, with feedback from these reviews used to improve the GNN’s accuracy over time.

Original source → Deals on Clipraptor.com →