Yes sir, that are CSS and JS file. I think LScache plugin working in server side, so hacker can detected real ip. Two day ago, I turn off plugin and it not leak real ip. I can't confirm it's LSCache, but I can't find another reason.
I don't know how they can know the real ip of the website. but i check the log history and see a lot of requests to /wp-content/litespeed/... i think the problem is with this plugin.