Website Security & Threat Management
How Cloudflare’s client-side security made the npm supply chain attack a non-event

How Cloudflare’s client-side security made the npm supply chain attack a non-event

10/24/2025 · Bashyam Anant, Juan Miguel Cejuela, Zhiyuan Zheng, Denzil Correa, Israel Adura, Georgie Yoxall

What this post added

Introduces and details Cloudflare Page Shield's ML-based malicious JavaScript detection capabilities, specifically highlighting its effectiveness against a recent npm supply chain attack. The post explains the use of Abstract Syntax Trees and message-passing graph convolutional networks (MPGCNs) for classifying scripts, discusses model evaluation metrics (Precision, Recall, F1), and outlines planned improvements including contextual data integration and consolidation of classifiers.

Read the original post ↗