It was reported that Cloudcms.com was hosting keylogging malware. This website allegedly was loading the script at the time of compromise as reported by https://publicwww.com/websites/%22code.cloudcms.com%2Falpaca%2F%22/ with the cypher snippet =text/css href=//code.cloudcms.com/alpaca/1.5.17/bootstrap/alp