Brevo supply-chain attack injected ClickFix scripts on customer sites
Executive Summary
Brevo confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its own websites and JavaScript files embedded on customer sites, enabling malware distribution. The attack leveraged the compromised API key to modify content served to visitors, turning legitimate sites into vectors for malicious payloads.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-17T17:11:34+00:00 - Category: threat-intel
Original Description: Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
"No one can make you feel inferior without your consent."
— Eleanor Roosevelt