Lifestyle

Cloudflare says four hidden JavaScript campaigns hit online shops while scanners missed them and pages looked normal

On 16 September 2026, Cloudflare said its Page Shield machine learning model found four malicious campaigns, made up of eight pieces of harmful code, running on online shops' live traffic. Seven of the eight were not in the public scanning service VirusTotal. The code mainly targeted shops' affiliate commissions and data. Here is what Cloudflare says and why it matters.

About 6 min read

Cloudflare says four hidden JavaScript campaigns hit online shops while scanners missed them and pages looked normal
Image: Mokaair (Original editorial artwork)

What happened

On 16 September 2026, Cloudflare published a post on its official blog, written by Juan Miguel Cejuela, Zhiyuan Zheng and Denzil Correa. JavaScript is the code that websites send to run inside a visitor's web browser. According to Cloudflare, Page Shield ML, a machine learning (ML) system in its client-side security product, which watches the code running in visitors' browsers, found four malicious campaigns in the wild. Together they involved eight malicious payloads, meaning eight pieces of harmful code. Cloudflare says detection was automated, and staff checked each case only after the system had flagged it.

VirusTotal and URLScan are widely used services for checking files and websites for malicious content. Cloudflare says that when it later rechecked with these security scanning tools, seven of the eight payloads were entirely absent from VirusTotal, and URLScan did not give a malicious verdict for any of them. Page Shield ML, by contrast, caught all eight in live traffic. As an example, the company said one version belonging to the Lnkr family had been indexed by URLScan for nearly two and a half years and always showed "No classification", including in a direct scan in January 2024. VirusTotal now flags it as malicious, but public records do not show when it first did so.

Cloudflare says four hidden JavaScript campaigns hit online shops while scanners missed them and pages looked normal
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

The four malicious campaigns at a glance

Many online shops pay an affiliate commission, a referral fee, to partners who send them customers. Several of these campaigns targeted that system. Cloudflare says the four campaigns share no common signature (a known pattern that security tools look for) or concealment technique. One of them activates only when the visitor's device, country, time, referring website or browser state meets certain conditions, so checking a page just once may not reveal it. The table below gives a general summary of Cloudflare's description and leaves out technical details.

Source: Cloudflare Blog, 16 September 2026
CampaignImpact as described by CloudflareNotes
1: After-hours affiliate commission hijackingHijacks affiliate commissionsCloudflare says it found five related versions: two active, three paused
2: Zero-click affiliate commission theftSteals affiliate commissions without the user clickingSends affiliate requests in a hidden way
3: Old search hijacker turned storefront backdoorTracks users and opens a backdoor that can remotely run any JavaScriptLoads code from remote servers when certain conditions are met
4: Paid mobile traffic cloakerHides mobile visitors who arrived via tagged ad campaigns from the shop, tries to replace ads and analytics, and hides customer supportIncludes a list of 325 IP address fragments and disables 9 monitoring or analytics tools

Taking campaign 1 as an example, Cloudflare says shops could end up paying unearned commissions to accounts that brought in no customers, and could wrongly give a legitimate partner's referral credit to someone else.

How Cloudflare detects them

  • Graph neural network (GNN): Cloudflare says this model analyses JavaScript as a map of how the code's parts connect (a syntax tree), rather than as plain text. The same model previously found malicious npm packages (reusable code shared by developers) and a Magecart payment skimmer, a type of script that steals card details at checkout.
  • Second opinion from an AI language model: scripts the GNN flags as malicious, under 0.3% of analysed traffic, are reviewed by a lightweight large language model (LLM) running on Cloudflare's Workers AI. Customers receive an alert only when it agrees.
  • "Teachers" model group: leading AI models from about six model families each analyse suspicious scripts independently. Their votes are weighted by each model's Artificial Analysis Intelligence Index score, producing probabilities for four labels: benign, payment skimmer, other malware and cryptomining (secretly using a visitor's computer to generate cryptocurrency).
  • Human review: people only need to check scripts flagged as malicious or lacking a two-thirds majority; feeding these results back into training still partly relies on manual work.
  • Future plans: Cloudflare says it will soon use Cloudflare Sandbox for deeper analysis in an isolated environment.

What it means for general readers

For online shoppers, the kind of scripts Cloudflare describes mainly target the shop's own revenue and data, such as commission payments and analytics tools, while the page still looks normal. The backdoor described in campaign 3, however, allows other code to be loaded remotely, so the impact could widen. For people running online shops or websites, the key point of this research is that relying only on lists of known bad code or one-off scans may not catch scripts that activate only under specific conditions in time. That said, this is Cloudflare's view based on its own products, and readers should treat it as vendor research rather than a neutral evaluation.

Frequently asked questions

Who is affected?

According to Cloudflare, mainly online shops. The scripts can cost them money through unearned or misdirected affiliate commissions and can interfere with their analytics and ads. Their legitimate affiliate partners can also lose credit for referrals.

Did common scanning tools really miss them all?

According to Cloudflare's recheck, seven of the eight were not in VirusTotal, and URLScan did not give a malicious verdict for any of them. This is Cloudflare's own claim and has not been independently verified.

What do these scripts mainly do?

As Cloudflare describes it, they hijack or steal affiliate commissions, track users and open backdoors that load remote code, and hide some mobile visitors from shops while interfering with ads and analytics tools.

Why is a one-off scan not enough?

Cloudflare says one of the campaigns activates only when the device, country, time, referring website or browser state meets certain conditions, so a single check of a page may not reveal the malicious behaviour.

Does this article recommend buying Cloudflare products?

No. This article only relays research published by Cloudflare and does not constitute a recommendation to buy any product.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle