Brevo supply-chain attack injected ClickFix scripts on customer sites

Refract AI Intelligence Digest

BLUF

Attackers compromised Brevo’s infrastructure using stolen Cloudflare credentials to deploy malware across customer sites.

NEWS

Brevo confirmed that threat actors obtained a Cloudflare API key and used it to inject malicious ClickFix scripts into their platform and embedded JavaScript files. This compromise affected both Brevo’s own properties and third-party sites relying on Brevo’s code, facilitating widespread malware distribution.

Why I Care

This incident highlights the critical risk of API key management in supply chains, as a single credential leak can cascade to thousands of downstream customers, exposing them to drive-by downloads and malware infections without their direct knowledge.

Next Steps

Organizations using Brevo should audit their integrations for unexpected scripts immediately, while all companies must enforce strict API key rotation and least-privilege access controls by the end of this week to prevent similar credential-based compromises.

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.