Skip to content
DnsLister Forum

Where domain hunters compare notes

Shopify store briefly showed a fake Cloudflare “Win + R” CAPTCHA — how can I identify the source when it no longer appears?

Hi everyone, this was formatted by AI for better readability and because I am not a native English speaker, I run a Shopify store and need help investigating a possible security incident. I’m not a security professional.

My store displayed a fake Cloudflare “Checking your browser” overlay. After interacting with it, it instructed me to press Win + R, Ctrl + V, then OK.

I did not paste or execute the Windows command.

I saved the affected page’s DOM. Static inspection found:

  • A script pointing to cdn2.sendibt1[.]com/f.js.
  • A full-screen iframe using srcdoc, with clipboard-write permission.
  • JavaScript that retrieves a command from the same domain and copies it to the clipboard on a click.
  • An encoded fallback command referencing cdnstore2193[.]com.

I understand this matches a ClickFix-style attack. What I cannot establish is what injected the script in the first place.

The overlay appeared on my Windows/Chrome computer, including an incognito session. It subsequently stopped appearing. I’ve since tried my computer and three other PCs, including a mobile hotspot, without reproducing it. Two later HAR captures do not contain requests to the suspicious domains.

Relevant context:

  • I uploaded an updated Shopify theme and added a custom Meta tracking pixel that day.
  • Static checks of the theme export and pixel found none of the known malicious indicators. This was not a full professional audit.
  • The store uses third-party app scripts, including TripleWhale and Brevo/PushOwl. I have no evidence implicating either provider.
  • My Cloudflare account provides DNS for the Shopify storefront, with the main domain set to DNS-only. My Worker serves separate admin subdomains.
  • No unexpected account members were visible in the checks performed.
  • I removed several Chrome extensions afterward, but the overlay had already stopped appearing before their removal. I don’t know whether those extensions previously had incognito access.
  • Windows Defender is active, and its available detection history showed no findings.

I have preserved the DOM captures and HAR files locally. I won’t post raw HAR files because they may contain session data.

What would you investigate next?

  1. How can I distinguish a transient compromised third-party script from local browser injection?
  2. Can the original loader’s source be determined from the saved DOM without a network capture of the attack?
  3. Which Shopify logs or forensic artifacts should I preserve or request before changing anything else?

I’m looking for a practical investigation and containment approach, rather than assuming that “it disappeared” means it is resolved.

Source: r/cybersecurity_help · by /u/Jakam181

Leave a Reply

Your email address will not be published. Required fields are marked *