Brevo supply-chain attack injected ClickFix scripts on customer sites
Attackers stole a long-lived Cloudflare API key hardcoded in Brevo's source code and, via a malicious Cloudflare Worker, replaced content on brevo.com, sendinblue.com, and sibforms.com for about 5.5 hours, as well as in form scripts and widgets embedded on customer sites. Sansec estimates up to 100,000 sites may be affected; visitors saw a fake Cloudflare check and ClickFix instructions.
- Compromise window: September 14, 16:07–20:30 UTC
- Cloudflare key with full rights was hardcoded in code
- Sansec estimates up to 100,000 sites affected
- Malicious WordPress plugin masqueraded as Web Media Optimizer
Read next
Security