DEV Community

polar
polar

Posted on

Cloudflare Hack

Recently, my API (Just a Cloudflare Worker) was taken over by some sort of malware. Someone managed to create a new access token on my account and use it to create a secret secondary worker to affect all of my domains, injecting a fake CAPTCHA prompt in the center of the screen that made the unsuspecting visitor paste a command into the terminal.

Luckily, with my background in Cybersecurity and assisting the FBI multiple times, I traced down the person who did it. They're in Iceland, so not much I could do. But for everyone out there, please make sure you're storing your tokens SAFELY in SECRET ENVIRONMENTAL VARIABLES, and for vibecoders, DON'T PASTE API KEYS AND TOKENS willynilly.

Top comments (0)