Brevo Supply Chain Attack Injects Malware into Over 100,000 Websites
A sophisticated supply chain attack has compromised a popular customer engagement platform, injecting malware into more than 100,000 websites. Brevo, which provides services to businesses and individuals alike, was hacked through a vulnerability in its Single Sign-On (SSO) functionality, allowing attackers to access sensitive information and deploy malicious code.
The breach began on September 10 when a threat actor exploited a vulnerability in Brevo’s SAML SSO system, gaining unauthorized access to 138 accounts. One of these accounts belonged to Trezor, a cryptocurrency storage provider, which raises concerns about the potential theft of sensitive financial data. The attackers sent phishing emails from six compromised accounts and exported contacts from 43 others, according to an incident notice issued by Brevo.
However, this was just the beginning. On September 14, the attackers returned, using a compromised Cloudflare API key to deploy a malicious worker script on brevo.com and sibforms.com. The script, which was active for approximately five and a half hours before being removed, injected malware into three JavaScript files that Brevo’s customers embed into their websites. This allowed the attackers to execute social engineering attacks on website visitors, attempting to trick them into running malicious code on their computers.
The malware, known as “ClickFix,” presented a fake Cloudflare verification page instructing users to paste and run a command on their computer. On WordPress sites embedding Brevo widgets, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator. This could have led to further compromise of website security.
According to cybersecurity firm Sansec, the malware was served for approximately four hours, impacting more than 100,000 websites. Brevo recommends that all sites using their services be reviewed for potential compromise, with administrators checking for unauthorized plugin installations and site visitors scanning their machines for malware if they were served the fake verification pages.
This supply chain attack highlights the importance of secure coding practices and robust security measures in software development. It also underscores the need for organizations to regularly review and update their third-party dependencies to prevent similar attacks from occurring in the future. By taking proactive steps to identify and address vulnerabilities, businesses can minimize the risk of falling victim to a supply chain compromise.
If you use Brevo services or have embedded their widgets on your website, it is essential to take immediate action to secure your site. Check for any unauthorized plugin installations, review your website’s logs for suspicious activity, and advise your users to be cautious when interacting with your site. Remember that even if the malicious code has been removed, your website may still be vulnerable to further attacks. Stay vigilant and prioritize security in your online operations.
Source: SecurityWeek — 2026-09-18