Cloudflare's Page Shield ML detected four malicious JavaScript campaigns on storefronts that security scanners like VirusTotal and URLScan missed. The ML model uses graph neural networks and large language models to analyze JavaScript behavior patterns in live traffic, catching obfuscated scripts designed to steal affiliate revenue, hijack clicks, and tamper with analytics without relying on known signatures.
Magic Actions for YouTube, a 1M+ user Chrome extension, was flagged as malware by Chrome despite being clean in Google Search Console and Safe Browsing. Investigation revealed an AI vendor (ExodiaLabs) on VirusTotal hallucinated a false security threat, which automated systems ingested and propagated to trigger client-side enforcement and account suspension.