Attackers used a stolen Cloudflare API key to inject malicious scripts into Brevo websites and customer-facing components. The Brevo supply-chain attack exposed visitors to ClickFix lures and targeted WordPress administrators with a persistent backdoor.

Attackers Compromise Cloudflare API Key

Brevo confirmed that attackers obtained a long-lived Cloudflare API key with full account permissions.

The customer relationship management and digital marketing company had hardcoded the credential in its application source code. Consequently, the attackers could create Cloudflare Workers, routes and DNS records across Brevo’s zones.

Moreover, their activity did not trigger an alert.

The attackers used the key to create a malicious Cloudflare Worker on September 14. It modified content at the content delivery network edge for around five and a half hours.

The incident affected pages across Brevo and its former Sendinblue domain. It also reached Brevo login, account, onboarding and form services.

In addition, the Worker altered several JavaScript components that customers embed on their own websites. These included Brevo forms, the Conversations widget and SDK loader scripts.

Edge Worker Bypasses Integrity Checks

The malicious Worker modified responses as Cloudflare delivered them to website visitors. Therefore, the attackers did not need to change Brevo’s original servers or files.

The Worker also removed security headers, including Content Security Policy protections. As a result, standard file integrity checks failed to detect the injected content.

Brevo said the attackers may have obtained the API key as early as late August. However, the company found no evidence of malicious activity before September 14.

After discovering the compromise, Brevo removed the Worker and its routes. The company placed the confirmed exposure window between 16:07 and 20:30 UTC.

Brevo then revoked the stolen key and any credentials created through it. Additionally, the company removed the hardcoded secret from its source code.

The response team also deleted attacker-controlled hostnames and cleared the company’s edge caches.

According to Brevo, the incident did not affect its application, API or email delivery infrastructure. The company also found no impact on customer account data.

ClickFix Lures Target Website Visitors

Security company Sansec first reported the Brevo supply-chain attack. It estimated that the affected components may have exposed as many as 100,000 websites.

Visitors to compromised pages encountered a fake Cloudflare verification screen. The page then displayed ClickFix instructions that urged Windows users to run a command.

ClickFix attacks use fake technical problems or verification requests to manipulate victims. Instead of exploiting a software vulnerability directly, the attackers convince users to execute the malicious command themselves.

Sansec confirmed that the malicious subdomains stopped resolving on September 15. It also found that Brevo’s affected files no longer contained the injected content.

Malicious Script Targets WordPress Administrators

The campaign included an additional attack against WordPress websites that embedded an affected Brevo widget.

The injected script checked whether a visitor had logged in as a WordPress administrator. If so, it tried to upload a malicious plugin disguised as “Web Media Optimizer.”

Despite its legitimate-sounding name, the plugin operates as a persistent backdoor and JavaScript loader.

Once installed, it hides from the normal WordPress plugin list. It also copies itself into the must-use plugins directory, which helps it remain active.

The plugin then contacts an attacker-controlled server at regular intervals. That server provides an encoded address for additional JavaScript.

Next, the plugin injects the remote script into pages shown to website visitors. The script can display another ClickFix lure and continue spreading the attack.

WordPress Backdoor Provides Persistent Access

The malicious plugin stores a backup copy of the last working JavaScript address.

Therefore, it can continue loading malicious code even if the main attacker-controlled server becomes unavailable. This feature makes the infection more resilient to infrastructure disruptions.

More seriously, the plugin contains a hardcoded authentication key. Attackers can use it to create a valid WordPress administrator session without knowing the account password.

This capability gives them extensive control over an infected website. For example, they could change content, install additional malware or access sensitive administrative features.

Administrators Should Check for Suspicious Plugins

WordPress administrators face the greatest risk if they visited an affected website while logged in on September 14.

They should review all plugins installed or activated on that date. In particular, administrators should look for unfamiliar entries or suspicious files inside the must-use plugins directory.

If they find signs of compromise, they should remove the malicious components and rotate all administrator passwords. They should also invalidate active sessions and inspect the site for further modifications.

Because the plugin can hide from the standard interface, checking the website’s files remains essential.

Brevo Recently Disclosed Another Security Incident

Brevo disclosed a separate single sign-on incident on September 10. During that attack, threat actors hijacked customer accounts and launched phishing campaigns.

Cryptocurrency wallet company Trezor reported that related phishing emails reached 347,000 addresses. According to the company, attackers successfully compromised at least 2,500 recipients.

However, Brevo has not confirmed any connection between that incident and the Cloudflare API key compromise.

The two incidents used different attack methods. Nevertheless, they both demonstrate how criminals can abuse trusted marketing infrastructure to reach large numbers of potential victims.


0 responses to “Brevo Supply-Chain Attack Injects ClickFix Malware”