bleeping-computer · Crawled Sep 17, 2026

Brevo supply-chain attack injected ClickFix scripts on customer sites

6 IoCs
Read original article ↗

AI Summary

Brevo suffered a supply-chain attack where attackers stole a long-lived Cloudflare API key hardcoded in source code, allowing them to deploy a malicious Cloudflare Worker that injected malicious ClickFix scripts into Brevo's web assets. The compromised scripts were distributed to customer sites embedding Brevo components, affecting up to 100,000 websites. On WordPress sites, the attack attempted to upload a malicious plugin called 'Web Media Optimizer' that acts as a persistent backdoor and injects further malicious JavaScript, including fake Cloudflare verification pages prompting users to run harmful commands.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
Domain cdn10[.]sendibt1[.]com Details →
Domain yelahaye[.]surf Details →
Domain boiseno[.]club Details →
Domain glegchner[.]com Details →
Domain corralos[.]beer Details →
Filename wm.zip Details →