logo

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

ID: 1eabfc11-c208-5f0a-84f7-f8c4490ee267

STIX ID: report--1eabfc11-c208-5f0a-84f7-f8c4490ee267

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-09-18

Date Updated: 2026-09-18

...
...

Attackers abused a compromised long-lived Cloudflare API key for Brevo to deploy a malicious Cloudflare Worker (active ~5.5 hours, serving malware ~4 hours) that injected scripts into brevo.com, sibforms.com, and third-party sites using Brevo-embedded JavaScript. The payload performed ClickFix social-engineering to trick visitors into executing attacker-supplied commands and attempted to install a malicious WordPress plugin when administrator sessions visited, potentially affecting over 100,000 websites; Brevo recommends auditing WordPress plugins, rotating credentials, and scanning affected users' machines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.