Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Brevo supply-chain attack injected ClickFix scripts on customer sites

Brevo confirmed that attackers used a stolen Cloudflare API key to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites. The scripts were used to distribute malware.

According to Brevo's post-mortem, the attackers created a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours on September 14, 2026. The exposure window was 16:07 to 20:30 UTC and affected pages on brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com, along with Brevo forms, the Brevo Conversations widget, and Brevo SDK loader scripts.

Brevo said the long-lived key had full account permissions and was hardcoded in application source code. The company said app.brevo.com, its API, email delivery infrastructure, and customer account data were not affected. It also said the key may have been compromised in late August, with no evidence of earlier malicious activity.

Security firm Sansec said the incident may have affected up to 100,000 websites. It reported that the attack began between 16:05 and 20:13 UTC on September 14, 2026, and that malicious subdomains stopped resolving on September 15, 2026.

On WordPress sites, the malware could install a backdoor plugin disguised as “Web Media Optimizer.” Brevo did not say whether this incident was connected to a separate SSO breach disclosed on September 10. Trezor said on September 11 that phishing reached 347,000 email addresses and compromised at least 2,500 users.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.