A sophisticated supply-chain attack has left thousands of websites vulnerable to malware distribution after attackers injected malicious scripts into customer sites. Brevo, a cloud-based customer relationship management (CRM) platform, confirmed that its systems were compromised when hackers stole a Cloudflare API key and used it to inject ClickFix scripts onto its own website and those of its customers.
The attack, which took place on September 14th between 16:07 and 20:30 UTC, affected several Brevo-owned domains, including brevo.com, sendinblue.com, and sibforms.com. The attackers used the compromised API key to create a malicious Cloudflare Worker that modified content at the CDN edge for approximately five and a half hours. This allowed them to inject scripts into customer sites without triggering any security alerts.
The impact of the attack was significant, with up to 100,000 websites potentially affected by the injection of malicious ClickFix scripts. The scripts were designed to display fake Cloudflare verification pages, followed by instructions urging visitors to run a command on their Windows machines. In some cases, the attackers also attempted to upload a malicious plugin to WordPress sites, which contained a persistent backdoor and JavaScript loader.
The compromised API key was used to create routes, DNS records, and workers across Brevo’s zones without triggering any security alerts. The company has since removed the malicious worker, revoked the compromised key, and purged its edge caches. However, the incident highlights the risks associated with supply-chain attacks and the importance of securing API keys and credentials.
The attack also raises questions about the security of Brevo’s systems, particularly in light of a separate incident disclosed by the company on September 10th. In that incident, attackers hijacked customer accounts and launched phishing attacks targeting customers of companies using Brevo. While Brevo has not confirmed whether the two incidents are connected, it is clear that the company faces significant security challenges.
For website administrators, this attack serves as a reminder of the importance of regularly monitoring their sites for suspicious activity and ensuring that all software and plugins are up to date. It also highlights the need for robust security measures, including multi-factor authentication and regular backups, to prevent supply-chain attacks from succeeding in the future.
In practical terms, website administrators should review their dependencies and vendors, particularly those involved in CRM and digital marketing, to ensure they are not impacted by similar supply-chain attacks. Regularly monitoring API keys, credentials, and access controls is also crucial to preventing such incidents. By taking these steps, website owners can reduce the risk of falling victim to sophisticated supply-chain attacks like this one.
Source: Bleeping Computer — 2026-09-17