<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Brevo Supply Chain Attack Hit Up to 100,000 Websites

A stolen Cloudflare API key let attackers inject ClickFix malware into Brevo scripts for five hours on September 14. Check WordPress plugins now.
Content Team

Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.

On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.

The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo