Hi everyone, this was formatted by AI for better readability and because I am not a native English speaker, I run a Shopify store and need help investigating a possible security incident. I’m not a security professional.
My store displayed a fake Cloudflare “Checking your browser” overlay. After interacting with it, it instructed me to press Win + R, Ctrl + V, then OK.
I did not paste or execute the Windows command.
I saved the affected page’s DOM. Static inspection found:
- A script pointing to
cdn2.sendibt1[.]com/f.js. - A full-screen iframe using
srcdoc, with clipboard-write permission. - JavaScript that retrieves a command from the same domain and copies it to the clipboard on a click.
- An encoded fallback command referencing
cdnstore2193[.]com.
I understand this matches a ClickFix-style attack. What I cannot establish is what injected the script in the first place.
The overlay appeared on my Windows/Chrome computer, including an incognito session. It subsequently stopped appearing. I’ve since tried my computer and three other PCs, including a mobile hotspot, without reproducing it. Two later HAR captures do not contain requests to the suspicious domains.
Relevant context:
- I uploaded an updated Shopify theme and added a custom Meta tracking pixel that day.
- Static checks of the theme export and pixel found none of the known malicious indicators. This was not a full professional audit.
- The store uses third-party app scripts, including TripleWhale and Brevo/PushOwl. I have no evidence implicating either provider.
- My Cloudflare account provides DNS for the Shopify storefront, with the main domain set to DNS-only. My Worker serves separate admin subdomains.
- No unexpected account members were visible in the checks performed.
- I removed several Chrome extensions afterward, but the overlay had already stopped appearing before their removal. I don’t know whether those extensions previously had incognito access.
- Windows Defender is active, and its available detection history showed no findings.
I have preserved the DOM captures and HAR files locally. I won’t post raw HAR files because they may contain session data.
What would you investigate next?
- How can I distinguish a transient compromised third-party script from local browser injection?
- Can the original loader’s source be determined from the saved DOM without a network capture of the attack?
- Which Shopify logs or forensic artifacts should I preserve or request before changing anything else?
I’m looking for a practical investigation and containment approach, rather than assuming that “it disappeared” means it is resolved.
Source: r/cybersecurity_help · by /u/Jakam181