Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026 Industry stats Updated Sep 2026 All domains worldwide 401.6M registered names +2.3% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 40.7% of all sites · 58.9% of CMS sites W3Techs · 1 Sep 2026 Shopify 5.3% of all sites · 7.7% of CMS sites W3Techs · 1 Sep 2026 Wix 4.2% of all sites · 6.1% of CMS sites W3Techs · 1 Sep 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Sep 2026 Joomla 1.1% of all sites · 1.7% of CMS sites W3Techs · 1 Sep 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Sep 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Sep 2026 No CMS detected 30.9% of all sites W3Techs · 1 Sep 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Deal Automattic → WebHosting.com domain · Automattic acquired the WebHosting.com domain in July 2026. No public press release or purchase price disclosed; domain now resolves to a 'coming soon' page with Automattic branding. No hosting business or customer migration was included in the deal. 2026
Security Abuse & Phishing Cloudflare

Cloudflare ML detects 4 hidden client-side malware campaigns

Page Shield AI caught eight malicious JavaScript payloads evading public scanners.

Cloudflare ML detects 4 hidden client-side malware campaigns
Arnold Francisca · Unsplash

Client-side malware on e-commerce sites can operate undetected for years, siphoning revenue and data while storefronts appear functional. Cloudflare’s Page Shield machine learning system recently uncovered four such operations, comprising eight malicious JavaScript payloads that evaded public security scanners like VirusTotal and URLScan. The findings highlight gaps in traditional signature-based detection and the need for continuous, behavior-aware monitoring of browser-executed code.

How the attacks evaded detection

The eight payloads were not flagged by VirusTotal or URLScan despite some being publicly accessible for over two years. One payload from the Lnkr malware family, for example, remained unclassified on URLScan for nearly 30 months, including during a direct scan in January 2024. VirusTotal later marked it as malicious, but the timeline of that verdict remains unclear. Cloudflare’s system, by contrast, detected all eight payloads in live traffic by analyzing JavaScript behavior rather than relying on known signatures or URLs.

The campaigns employed diverse evasion tactics. Some scripts activated only under specific conditions—such as mobile devices, certain geographic regions, or particular times of day—while others used invisible iframes or self-clicking links to execute affiliate theft without user interaction. One operation even disguised its delivery domain as a legitimate marketing agency, using typosquatting to blend in with routine third-party tags. These techniques allowed the malware to remain dormant during automated scans, only activating when real users visited the site.

Background

Background: Client-side malware executes in a user’s browser rather than on a server, often delivered via third-party scripts or compromised marketing tags. Unlike server-side attacks, it can operate without direct access to backend infrastructure, making detection harder for traditional security tools.

The four operations and their impact

Each campaign targeted different aspects of e-commerce operations:

  1. After-hours affiliate hijacker: Intercepted product clicks on mobile devices during specific time windows, redirecting users through attacker-controlled affiliate links. The script used a three-day cooldown to avoid repeated execution on the same device, while MutationObservers tracked dynamically loaded product tiles to ensure late-arriving elements were also hijacked.

  2. Clickless affiliate theft: Sent covert affiliate requests via hidden iframes or auto-clicked links, bypassing user interaction entirely. The script ignored geolocation data from its own IP lookup, instead using hardcoded time gates to determine when to execute. A one-hour throttle cookie prevented rapid re-firing, while a fallback mechanism clicked hidden links if the iframe failed.

  3. Search saboteur turned backdoor: Originally part of the Lnkr malware family, this script repurposed dormant search-redirect modules to open a remote backdoor on a retailer’s site. It sent telemetry to attacker-controlled domains and could load arbitrary JavaScript without modifying server files. Anti-analysis features, such as pausing execution when security-related keywords were detected, further obscured its behavior.

  4. Paid-mobile cloaker: Targeted high-value mobile traffic from paid campaigns, disabling analytics tools, support chats, and ad attribution systems. The script used a 325-entry IP denylist and geographic filters to avoid triggering on corporate networks or security analysts’ devices. It also replaced legitimate ad publisher IDs with attacker-controlled ones, potentially diverting revenue.

Why continuous monitoring matters

The campaigns demonstrate that static scans and one-time crawls are insufficient to detect client-side malware. Many scripts remained dormant unless specific conditions were met—such as device type, time of day, or geographic location—making them invisible to traditional security tools. Cloudflare’s approach combines a graph neural network (GNN) to analyze JavaScript structure with a lightweight LLM for secondary validation, reducing false positives while maintaining high detection rates.

For complex cases, the system employs an ensemble of frontier AI models to analyze suspicious scripts independently. Disagreements between models are treated as signals, with human reviewers focusing only on scripts lacking a clear consensus. This feedback loop helps refine detection over time, particularly for heavily obfuscated payloads.

For professionals

For professionals: E-commerce operators should audit third-party scripts and marketing tags for typosquatted domains or unexpected behavior. Enabling continuous client-side monitoring can help detect malicious activity that evades traditional scanners, particularly for campaigns targeting high-value traffic or affiliate revenue.

Companies mentioned

Cloudflare

Discussion · coming soon

Be the first to join the thread when community discussion launches.