Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Attackers breached Brevo, hijacked a Cloudflare API key, and injected ClickFix malware scripts served to visitors of 100,000+ websites including Trezor.
Brevo was hacked on September 10, 2026, via a vulnerability in its SAML SSO handling, exposing 138 accounts including crypto storage provider Trezor; attackers phished from six accounts and exported contacts from 43. On September 14 they used a compromised long-lived Cloudflare API key to deploy a worker that injected malicious scripts into brevo.com, sibforms.com, and three JavaScript files embedded in customer websites. The scripts showed fake 'Cloudflare, verify you are human' pages using the ClickFix technique and tried to install a malicious WordPress plugin for logged-in admins. Sansec estimates more than 100,000 websites were affected during roughly four hours; the API key was first misused in late August 2026.
- Initial September 10 access exploited a SAML SSO handling flaw, compromising 138 accounts.
- Compromised Cloudflare API key deployed a worker injecting scripts into customer-embedded JavaScript files.
- Fake 'Cloudflare verify you are human' pages used ClickFix to trick users into running commands.
- On WordPress, the script attempted to install a plugin when a logged-in admin visited.
- Sansec estimates 100,000+ websites served malware for roughly four hours; admins should audit plugins.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | brevo.com | eploy a worker. That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brev |
| domain | sibforms.com | . That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers emb |
Full article377 words · extracted from securityweek.com · click to collapse
Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites.
Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor.
The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice.
The company closed the unauthorized access, but the attackers returned on September 14, when they used a compromised long-lived Cloudflare API key to deploy a worker.
That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites, the company said in a post-mortem.
“The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo explains.
Advertisement. Scroll to continue reading.
On the WordPress websites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator.
The malicious worker was active for roughly five and a half hours before Brevo removed it and revoked the compromised API key and credentials.
“Our investigation indicates the key was first misused in late August 2026. We have found no injection of malicious content into customer-facing pages before 14 September,” Brevo said.
According to cybersecurity firm Sansec, the malware was served for roughly four hours, and more than 100,000 websites were likely impacted.
The company recommends that all sites using Brevo be reviewed for potential compromise. Administrators should check for unauthorized plugin installations, and site visitors should check their machines for malware if they were served the fake verification pages.
“Brevo is no longer serving malicious code. However, your WordPress site may have been backdoored, and your customers may have fallen for the ClickFix scam,” Sansec notes.
Related: Critical Orkes Conductor Vulnerability Exploited in Attacks
Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Related: Rust Supply Chain Attack Linked to North Korean Hackers
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/