A massive supply chain attack has compromised over 100,000 websites by injecting malware through a customer engagement platform called Brevo. The attackers exploited a vulnerability in Brevo’s handling of security protocols to access hundreds of accounts, including one belonging to cryptocurrency storage provider Trezor, and used this access to deploy malicious code on multiple websites.
Brevo was initially hacked on September 10 when an attacker exploited a vulnerability in the company’s Single Sign-On (SSO) system. The threat actor accessed 138 accounts, including Trezor’s, and sent phishing emails from six of these accounts, exporting the contacts of 43 accounts in the process. Brevo closed this unauthorized access but unfortunately, the attackers returned on September 14, using a compromised Cloudflare API key to deploy a malicious worker.
This worker injected malware into Brevo’s own website (brevo.com), as well as three JavaScript files that Brevo’s customers embed into their websites. The malware showed visitors a fake “Cloudflare verification” page, which instructed them to paste and run a command on their computer, a social engineering technique known as ClickFix. On WordPress sites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator.
The compromised worker was active for roughly five hours before Brevo removed it and revoked the affected API key and credentials. According to cybersecurity firm Sansec, the malware was served for approximately four hours, impacting over 100,000 websites in the process. While Brevo has since stopped serving malicious code, administrators should be on high alert as their WordPress sites may have been compromised.
Sansec recommends that all websites using Brevo be thoroughly reviewed for potential compromise. Administrators should check for unauthorized plugin installations and site visitors should scan their machines for malware if they were shown the fake verification page. This incident highlights the importance of monitoring third-party integrations and staying vigilant about potential security threats in the supply chain.
In practical terms, website administrators using Brevo should immediately review their sites for any signs of compromise, such as suspicious plugin installations or unusual visitor behavior. They should also ensure that all API keys and credentials are up-to-date and secure to prevent similar attacks in the future.
Source: SecurityWeek — 2026-09-18