logo

Brevo Supply-Chain Attack Infected Over 100,000 Websites

ID: 6d461a07-252e-5ca6-8f82-9e5fac1b55f6

STIX ID: report--6d461a07-252e-5ca6-8f82-9e5fac1b55f6

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-09-18

Date Updated: 2026-09-19

Author: Pierluigi Paganini

...
...

Brevo (formerly Sendinblue) was compromised when attackers obtained a long‑lived Cloudflare API key and deployed a malicious Cloudflare Worker that injected scripts into Brevo’s CDN assets and three JavaScript files embedded in customer sites, potentially infecting over 100,000 websites; the attack displayed fake "prove you’re human" overlays to visitors and could silently install a hidden WordPress plugin for logged‑in admins, all while remaining invisible to origin integrity checks and standard scanners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.