Brevo Supply Chain Attack Hit Up to 100,000 Websites
Want more insights like this?
Security firm Sansec estimates that a supply chain attack on customer engagement platform Brevo pushed malicious code to as many as 100,000 websites. A separate incident on September 10 saw attackers exploit Brevo's SAML SSO handling to reach 138 customer accounts, including Trezor's, which reported phishing that reached 347,000 user email addresses and compromised at least 2,500. Brevo has not said the two incidents are linked.
On September 14, attackers used a compromised Cloudflare API key — long-lived, fully permissioned, and hardcoded in Brevo's source code — to deploy a worker that injected malware into Brevo's domains and three JavaScript files customers embed. Because the worker rewrote responses at the CDN edge and stripped Content-Security-Policy headers, Brevo's origin files stayed untouched and standard integrity checks detected nothing.
The worker ran roughly five and a half hours, serving a fake Cloudflare verification page that used ClickFix prompts to get visitors running commands themselves. WordPress administrators logged in during the window were prompted to install a plugin from an attacker domain. Review September 14 logs for plugin uploads, compare your filesystem against the admin plugin list, and rotate administrator passwords if anything turns up.
Source: SecurityWeek