When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
- ID
- 25259
- Status
- summarized
- Published
- 17 Sep 2026, 4:06 AM
- Fetched
- 17 Sep 2026, 6:07 AM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/client-side-security-finds-4-malicious-campaigns/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 6.0
- Created
- 17 Sep 2026, 6:07 AM
- Tags
- Audience
- developerssaas_founders
What happened
Cloudflare details four malicious JavaScript campaigns (eight payloads) caught by their Page Shield ML model on live storefronts, where seven of eight payloads were absent from VirusTotal and URLScan returned no malicious verdict for any. One payload sat indexed by URLScan for nearly 2.5 years with 'No classification' before Page Shield ML independently surfaced it. The payloads used conditional activation—dormant unless device, country, time, referrer, or browser state matched—making one-time page scans ineffective.
Why it matters
If you run an e-commerce storefront or any site loading third-party JavaScript, hash- and reputation-based scanners have a measurable blind spot: a payload can be indexed for years without a malicious label. You should evaluate whether your client-side monitoring watches script behavior over time rather than relying on static scans, especially for affiliate hijacking and click interception which quietly drain revenue without breaking checkout.
Discussion angle
The gap between 'file is known' and 'file is classified malicious' can span years—what does this mean for teams relying on CSP reports or SRI hashes alone, and is behavioral ML the only scalable answer for conditional/dormant scripts?