Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2902+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
NEWS

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

A stolen Cloudflare API key let attackers hijack Brevo's site and embedded scripts for hours, hitting 100,000+ sites with ClickFix malware.

Dylan H.

News Desk

September 18, 2026
2 min read

A Compromised API Key, a Malicious Worker

Attackers used a compromised, long-lived Cloudflare API key belonging to email-marketing platform Brevo to deploy a malicious Cloudflare Worker on September 14, 2026. Investigation later revealed the key had actually been misused as early as late August 2026, well before the visible injection event.

Once deployed, the worker injected malicious scripts into brevo.com, sibforms.com, and three JavaScript files embedded on customer-owned websites — meaning the blast radius extended well beyond Brevo's own infrastructure into every site running Brevo's embedded scripts.


What the Injected Script Did

The malicious payload had two distinct functions:

  1. ClickFix social engineering — a fake "Cloudflare, verify you are human" page was displayed to visitors, attempting to trick them into copying and executing a malicious command themselves (the increasingly common ClickFix technique).
  2. WordPress targeting — on WordPress sites, the script attempted to install and execute a malicious plugin if the visiting session held administrator credentials, giving attackers a persistent foothold independent of the original injection point.

Scale and Duration

According to cybersecurity firm Sansec, the malicious worker was active for roughly five and a half hours before removal, with malware actually served to visitors for approximately four hours of that window. Sansec estimates more than 100,000 websites were likely impacted given the reach of Brevo's embedded scripts across its customer base.

No specific threat actor has been publicly attributed to the attack.


Remediation

Brevo is advising affected site operators to:

  • Audit WordPress installations for unauthorized or unrecognized plugins installed during the exposure window and remove any found
  • Rotate credentials, particularly for any admin accounts that may have browsed a site during the active injection period
  • Advise site visitors who encountered the fake "verify you are human" page to scan their machines for malware, since ClickFix relies on the victim manually running attacker-supplied commands

More broadly, this incident is another reminder that long-lived API keys for infrastructure providers like Cloudflare are a high-value target — scoping keys narrowly, setting short expirations, and monitoring for anomalous Worker deployments can all reduce the blast radius when a key is eventually compromised.

Sources

  • SecurityWeek — Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
#Supply Chain#Cloudflare#Malware#ClickFix#WordPress

Related Articles

Trezor: 347,000 Users Targeted in Phishing Attacks After Brevo Breach

A breach at email platform Brevo let attackers hijack Trezor's newsletter account and phish 347K addresses; 2,500 users clicked the malicious link.

4 min read

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

A newly observed ClickFix campaign impersonates Cloudflare's CAPTCHA verification pages to deliver the Python-based Infiniti Stealer to macOS users via a...

4 min read

Police Cleans Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp

International law enforcement cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish...

3 min read
Back to all News