Cloudflare Page Shield Uses Machine Learning to Detect Four Stealthed Client-Side Campaigns

Cloudflare reported that its Page Shield machine learning models successfully flagged four active, malicious client-side campaigns designed to evade traditional signature-based security tools. These campaigns relied on browser-executed JavaScript to hijack affiliate commissions, manipulate analytics data, and execute clickjacking attacks while the host e-commerce sites appeared to function normally.
Related tools
Recommended tools for this topic
These picks prioritize high-intent tools relevant to this topic. Some links may include partner or affiliate tracking.
A strong security and edge platform match across CDN, Zero Trust, and app protection.
View CloudflareA high-relevance security pick for identity, secret management, and team access control.
View 1PasswordStrong for identity, OIDC, and B2B auth readers evaluating implementation tradeoffs.
View Auth0Comparison
| Aspect | Before / Alternative | After / This |
|---|---|---|
| Detection Mechanism | Static signatures, URL reputation, and sandbox dynamic analysis | Continuous behavioral profiling via client-side machine learning models |
| Response to Cloaked Scripts | Misses targeted scripts that require specific runtime conditions to execute | Identifies suspicious browser anomalies regardless of static file state |
| Vulnerability to Zero-Days | High, as seen by VirusTotal and URLScan failing to classify 7 of 8 payloads | Low, as Page Shield flags novel behaviors before global threat indicators update |
Action Checklist
- Deploy Cloudflare Page Shield on target e-commerce and sensitive client-facing domains This enables continuous client-side script auditing and behavioral analysis
- Audit existing third-party JavaScript dependencies for unauthorized modifications Look for older campaign variants like Lnkr that may have bypassed legacy scanners for years
- Establish Content Security Policies to restrict unauthorized external script execution CSP helps mitigate risks if a malicious script attempts to load external resources
Source: Cloudflare Blog
This page summarizes the original source. Check the source for full details.



