Browsers Under Siege: How Malicious Scripts Are Stealing Data Without Breaking Anything
New client-side skimming attacks can steal sensitive data without disrupting user experience, highlighting ongoing security challenges for web developers and users.
Client-side skimming attacks have emerged as a stealthy yet potent threat to web users. These sophisticated techniques allow attackers to harvest sensitive data such as login credentials and financial information without breaking the page's functionality or disrupting user experience. The crux of these attacks lies in their ability to inject malicious scripts into seemingly harmless pages, making them undetectable by traditional security measures.
Real-World Examples
The recent incidents highlighted by Sansec and Cloudflare underscore the severity of this issue:
- In January 2026, Sansec reported a browser-side keylogger running on an employee merchandise store for a major U.S. bank. This attack collected personal data, login credentials, and credit card information from unsuspecting users.
- In September 2025, attackers published malicious versions of widely used npm packages that could be bundled into front-end code, potentially exposing end-users to crypto-stealing in the browser if they were not vigilant about their dependencies.
These examples illustrate how even well-protected systems can fall victim to sophisticated skimming attacks. The key takeaway is that no matter how robust a website's security measures are, it only takes one malicious script tag for an attacker to gain unauthorized access and steal sensitive data.
New Cloudflare Security Measures
To address these growing threats, Cloudflare has taken significant steps by making its Client-Side Security Advanced (formerly Page Shield add-on) available on a self-serve basis. Additionally, domain-based threat intelligence is now complimentary for all customers using the free Client-Side Security bundle.
The move towards self-service indicates that Cloudflare aims to democratize advanced security features without requiring extensive technical expertise or sales engagement. This shift could significantly enhance web safety by empowering more users and developers with robust protection tools, even if they are not tech-savvy professionals.
Recommended for you




