Brevo supply-chain attack injected ClickFix scripts on customer sites

Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used a malicious Cloudflare Worker to inject ClickFix scripts into Brevo pages and customer-embedded JavaScript for several hours on September 14. The compromise also pushed a fake WordPress plugin called “Web Media Optimizer” to some sites, while Brevo says its core app, API, email delivery systems, and customer account data were not affected. #Brevo #Cloudflare #ClickFix #WebMediaOptimizer #WordPress

Keypoints

  • Attackers used a stolen Cloudflare API key with full permissions.
  • A malicious Cloudflare Worker altered Brevo content at the CDN edge for about five and a half hours.
  • The injected scripts showed a fake Cloudflare verification page and ClickFix instructions.
  • Some WordPress sites received a malicious plugin posing as “Web Media Optimizer” for persistence and backdoor access.
  • Brevo revoked the key, removed attacker infrastructure, and says core systems and customer data were not impacted.

Read More: https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/