THE CRUNCH
Cloudflare has detailed how its Page Shield machine learning model uncovered four distinct malicious JavaScript operations on live storefronts that were missed by standard security scanners. The system uses a graph neural network to analyse code structure and a large language model for verification, catching attacks that rely on conditional logic, obfuscation, or timing to stay hidden.
The attacks uncovered by Page Shield included affiliate commission hijacking, click interception, analytics suppression, and conditional code loading. Crucially, seven of the eight malicious payloads were absent from VirusTotal and URLScan, which failed to flag them despite being scanned directly. This highlights a blind spot where attackers can remain undetected until they execute on a specific victim.
Cloudflare's detection method treats JavaScript as a graph rather than flat text, allowing the system to recognise suspicious patterns even when code is minified or obfuscated. The GNN flags suspicious scripts, which are then reviewed by a large language model and, for complex cases, a cohort of frontier models acting as automated judges. This multi-stage process reduces false positives while maintaining high recall.
The attacker's goal was often to steal attribution or commissions rather than steal payment data. Cloudflare notes that a hash can be known long before the code is classified as malicious, meaning waiting for a signature is too late. The system demonstrates that ongoing browser visibility is essential to catch scripts that are designed to stay quiet until the right victim appears.


