Brevo supply-chain attack injected ClickFix scripts on customer sites
BLUF
Attackers compromised Brevo’s infrastructure using stolen Cloudflare credentials to deploy malware across customer sites.
NEWS
Brevo confirmed that threat actors obtained a Cloudflare API key and used it to inject malicious ClickFix scripts into their platform and embedded JavaScript files. This compromise affected both Brevo’s own properties and third-party sites relying on Brevo’s code, facilitating widespread malware distribution.
Why I Care
This incident highlights the critical risk of API key management in supply chains, as a single credential leak can cascade to thousands of downstream customers, exposing them to drive-by downloads and malware infections without their direct knowledge.
Next Steps
Organizations using Brevo should audit their integrations for unexpected scripts immediately, while all companies must enforce strict API key rotation and least-privilege access controls by the end of this week to prevent similar credential-based compromises.
Source: BleepingComputer ·