Client-side malware on e-commerce sites can operate undetected for years, siphoning revenue and data while storefronts appear functional. Cloudflare’s Page Shield machine learning system recently uncovered four such operations, comprising eight malicious JavaScript payloads that evaded public security scanners like VirusTotal and URLScan. The findings highlight gaps in traditional signature-based detection and the need for continuous, behavior-aware monitoring of browser-executed code.
How the attacks evaded detection
The eight payloads were not flagged by VirusTotal or URLScan despite some being publicly accessible for over two years. One payload from the Lnkr malware family, for example, remained unclassified on URLScan for nearly 30 months, including during a direct scan in January 2024. VirusTotal later marked it as malicious, but the timeline of that verdict remains unclear. Cloudflare’s system, by contrast, detected all eight payloads in live traffic by analyzing JavaScript behavior rather than relying on known signatures or URLs.
The campaigns employed diverse evasion tactics. Some scripts activated only under specific conditions—such as mobile devices, certain geographic regions, or particular times of day—while others used invisible iframes or self-clicking links to execute affiliate theft without user interaction. One operation even disguised its delivery domain as a legitimate marketing agency, using typosquatting to blend in with routine third-party tags. These techniques allowed the malware to remain dormant during automated scans, only activating when real users visited the site.
Background: Client-side malware executes in a user’s browser rather than on a server, often delivered via third-party scripts or compromised marketing tags. Unlike server-side attacks, it can operate without direct access to backend infrastructure, making detection harder for traditional security tools.
The four operations and their impact
Each campaign targeted different aspects of e-commerce operations:
-
After-hours affiliate hijacker: Intercepted product clicks on mobile devices during specific time windows, redirecting users through attacker-controlled affiliate links. The script used a three-day cooldown to avoid repeated execution on the same device, while MutationObservers tracked dynamically loaded product tiles to ensure late-arriving elements were also hijacked.
-
Clickless affiliate theft: Sent covert affiliate requests via hidden iframes or auto-clicked links, bypassing user interaction entirely. The script ignored geolocation data from its own IP lookup, instead using hardcoded time gates to determine when to execute. A one-hour throttle cookie prevented rapid re-firing, while a fallback mechanism clicked hidden links if the iframe failed.
-
Search saboteur turned backdoor: Originally part of the Lnkr malware family, this script repurposed dormant search-redirect modules to open a remote backdoor on a retailer’s site. It sent telemetry to attacker-controlled domains and could load arbitrary JavaScript without modifying server files. Anti-analysis features, such as pausing execution when security-related keywords were detected, further obscured its behavior.
-
Paid-mobile cloaker: Targeted high-value mobile traffic from paid campaigns, disabling analytics tools, support chats, and ad attribution systems. The script used a 325-entry IP denylist and geographic filters to avoid triggering on corporate networks or security analysts’ devices. It also replaced legitimate ad publisher IDs with attacker-controlled ones, potentially diverting revenue.
Why continuous monitoring matters
The campaigns demonstrate that static scans and one-time crawls are insufficient to detect client-side malware. Many scripts remained dormant unless specific conditions were met—such as device type, time of day, or geographic location—making them invisible to traditional security tools. Cloudflare’s approach combines a graph neural network (GNN) to analyze JavaScript structure with a lightweight LLM for secondary validation, reducing false positives while maintaining high detection rates.
For complex cases, the system employs an ensemble of frontier AI models to analyze suspicious scripts independently. Disagreements between models are treated as signals, with human reviewers focusing only on scripts lacking a clear consensus. This feedback loop helps refine detection over time, particularly for heavily obfuscated payloads.
For professionals: E-commerce operators should audit third-party scripts and marketing tags for typosquatted domains or unexpected behavior. Enabling continuous client-side monitoring can help detect malicious activity that evades traditional scanners, particularly for campaigns targeting high-value traffic or affiliate revenue.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 16 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 2 candidates
- Checking for duplicates — New story No existing article covers Cloudflare's Client-Side Security for storefronts.
- Checking for duplicates — New story pre_write:; No existing article covers Cloudflare's Client-Side Security for storefront protection.
- Writing the article — Draft created article_id=564 slug=cloudflare-ml-detects-4-hidden-client-side-malware-campaigns
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states 'One payload from the Lnkr malware family... remained unclassified on URLScan for nearly 30 months, including during a direct scan in January 2024.' The source confirms the 30-month timeline and January 2024 scan, but does not specify the exact calendar date of the scan. While the relative timing is correct, the specific month/year (January 2024) is not explicitly tied to a calendar date in the source. This is a minor discrepancy as the relative timeline is accurate.
- Quote integrity: No blockquotes are used in the draft, so this check is not applicable. However, the draft does not include any verbatim quotes from the source, which is compliant with the style guide.
- No copied phrasing: The draft paraphrases the source effectively, but the phrase 'client-side malware executes in a user’s browser rather than on a server' closely mirrors the source's 'Client-side malware executes in the browser.' While the meaning is identical, the phrasing is suspiciously similar. This is a minor issue as the rest of the draft avoids such echoes.
- Style compliance: The draft adheres to the structure and tone requirements, but the 'Background' block could be slightly more concise (4 sentences instead of the recommended 2-4). This is a minor deviation.
- Audience relevance and notability: The story is highly relevant to hosting/domains/DNS/email professionals, particularly those managing e-commerce security. The focus on client-side malware detection and evasion tactics provides actionable insights for operators.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Rejected library image #185: The candidate depicts Cloudflare's headquarters, which is unrelated to the article's focus on malware campaigns, client-side security, or machine learning detection. The topic requires imagery of malware, security threats, or detection mechanisms, not a company building.
- Assigning hero image — Unsplash unsplash_id=f77Bh3inUpE q=malicious JavaScript code on laptop screen picker=The article is about detecting malicious JavaScript malware campaigns using Cloudflare's ML model. Candidate 14 (alt='tu
- Linking related stories — Linked 3 relations from 361 candidates
- Linking related stories — Linked 3 relations from 361 candidates
- Linking related stories — Linked 3 relations from 361 candidates
- Linking related stories — Linked 3 relations from 361 candidates
- Linking related stories — Linked 3 relations from 357 candidates
- Linking related stories — Linked 4 relations from 354 candidates
- Linking related stories — Linked 4 relations from 351 candidates
- Linking related stories — Linked 4 relations from 348 candidates
- Linking related stories — Linked 4 relations from 346 candidates
- Linking related stories — Linked 4 relations from 346 candidates
- Linking related stories — Linked 4 relations from 346 candidates
- Linking related stories — Linked 4 relations from 342 candidates
- Linking related stories — Linked 4 relations from 340 candidates
- Linking related stories — Linked 4 relations from 339 candidates
- Linking related stories — Linked 4 relations from 338 candidates
- Linking related stories — Linked 4 relations from 337 candidates
- Linking related stories — Linked 4 relations from 333 candidates
- Linking related stories — Linked 5 relations from 332 candidates
- Linking related stories — Linked 2 relations from 330 candidates
- Linking related stories — Linked 2 relations from 329 candidates
- Linking related stories — Linked 2 relations from 329 candidates
- Linking related stories — Linked 5 relations from 329 candidates
- Linking related stories — Linked 2 relations from 329 candidates
- Linking related stories — Linked 2 relations from 329 candidates
- Linking related stories — Linked 2 relations from 329 candidates
- Linking related stories — Linked 2 relations from 329 candidates
- Linking related stories — Linked 2 relations from 329 candidates
- Linking related stories — Linked 5 relations from 329 candidates
- Linking related stories — Linked 2 relations from 328 candidates
- Linking related stories — Linked 2 relations from 328 candidates
- Linking related stories — Linked 2 relations from 328 candidates
- Linking related stories — Linked 2 relations from 328 candidates
- Linking related stories — Linked 2 relations from 327 candidates
- Linking related stories — Linked 5 relations from 327 candidates
- Linking related stories — Linked 5 relations from 327 candidates
- Linking related stories — Linked 2 relations from 327 candidates
- Linking related stories — Linked 2 relations from 326 candidates
- Linking related stories — Linked 2 relations from 326 candidates
- Linking related stories — Linked 2 relations from 326 candidates
- Linking related stories — Linked 2 relations from 326 candidates
- Linking related stories — Linked 2 relations from 326 candidates
- Linking related stories — Linked 2 relations from 325 candidates
- Linking related stories — Linked 5 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 1 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 1 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 5 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 1 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 5 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 1 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 5 relations from 323 candidates
- Linking related stories — Linked 2 relations from 320 candidates
- Linking related stories — Linked 2 relations from 320 candidates
- Linking related stories — Linked 5 relations from 320 candidates
- Linking related stories — Linked 2 relations from 320 candidates
- Linking related stories — Linked 2 relations from 320 candidates
- Linking related stories — Linked 1 relations from 320 candidates
- Linking related stories — Linked 2 relations from 323 candidates
- Linking related stories — Linked 4 relations from 323 candidates
- Linking related stories — Linked 2 relations from 324 candidates
- Linking related stories — Linked 2 relations from 325 candidates
- Linking related stories — Linked 2 relations from 325 candidates
- Linking related stories — Linked 5 relations from 326 candidates
- Linking related stories — Linked 1 relations from 327 candidates
- Linking related stories — Linked 2 relations from 328 candidates
- Linking related stories — Linked 2 relations from 328 candidates
- Publishing — Published cloudflare-ml-detects-4-hidden-client-side-malware-campaigns
- Mastodon — Posted https://mstdn.social/@hostingpaper/117304405618404995



Discussion · coming soon
Be the first to join the thread when community discussion launches.