Brevo supply chain attack injects malware into 100,000 websites
Summary
A supply chain attack involving Brevo has resulted in the injection of malware into approximately 100,000 websites. The attackers exploited a hardcoded Cloudflare API key in Brevo's source code to deploy malicious Workers, altering content delivered through the content delivery network (CDN). The injected code displayed fraudulent verification pages and triggered attempts to install WordPress plugins during admin visits. In response to the incident, Brevo revoked the compromised keys and assured that its core services, including the API and email infrastructure, were not affected.
Analysis
Brevo: Brevo is a digital marketing and customer relationship management platform that provides email marketing, automation tools, hosted forms, chat widgets, and SDKs for website integration. The company, formerly Sendinblue and based in Paris, serves organizations with these embedded components across customer sites. In this supply chain incident, attackers compromised Brevo's Cloudflare API key to inject malicious scripts into its JavaScript files and widgets, enabling malware distribution to sites using those resources. Incident Response: Brevo revoked the compromised credentials and confirmed that core services including its API and email infrastructure remained unaffected. Malware Delivery Method: The injected code presented fake verification pages leading to ClickFix instructions, while also attempting WordPress plugin installations on admin visits. Supply Chain Compromise: Attackers abused a long-lived Cloudflare API key hardcoded in Brevo's source code to create malicious Workers that altered content delivered via CDN.
Categories
tech
Related sources
- https://www.securityweek.com/eu-chief-warns-of-ai-powered-hacking-moves-to-rein-in-social-media/
- https://cyberinsider.com/100000-wordpress-sites-infected-via-brevo-supply-chain-attack/
- https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/
- https://frenchbreaches.com/blog/cyberattaque-chez-brevo-plus-de-100-000-sites-exposes-apres-le-piratage-du-geant-francais
- https://cyberpress.org/brevo-cdn-javascript-injection/
- https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
- https://whack.sh/news/brevo-kongtuke-clickfix-infrastructure
- https://the420.in/brevo-supply-chain-attack-cloudflare-clickfix-customer-websites/
- https://www.pcmag.com/news/hack-at-marketing-vendor-exploited-to-widely-spread-clickfix-malware-attack
- https://sansec.io/research/brevo-supply-chain-attack
- https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/
- https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/
- https://www.securityweek.com/catch-raises-5-million-for-ai-executive-assistant-with-guardrails/