bleeping-computer · Crawled Sep 17, 2026
Brevo supply-chain attack injected ClickFix scripts on customer sites
6 IoCs
Read original article ↗
AI Summary
Brevo suffered a supply-chain attack where attackers stole a long-lived Cloudflare API key hardcoded in source code, allowing them to deploy a malicious Cloudflare Worker that injected malicious ClickFix scripts into Brevo's web assets. The compromised scripts were distributed to customer sites embedding Brevo components, affecting up to 100,000 websites. On WordPress sites, the attack attempted to upload a malicious plugin called 'Web Media Optimizer' that acts as a persistent backdoor and injects further malicious JavaScript, including fake Cloudflare verification pages prompting users to run harmful commands.
AI-extracted · verify before operational use