Brevo Supply Chain Attack Hits 100,000 Sites via Stolen API Key
A compromised Cloudflare API key allowed attackers to inject malicious scripts into Brevo's infrastructure, affecting a vast number of customer websites.
A supply chain attack against Brevo, a marketing and email platform, has resulted in malicious code being injected into roughly 100,000 customer websites. According to SecurityWeek, the attackers leveraged a compromised API key to deploy a Cloudflare worker that injected malicious scripts. BleepingComputer adds that Brevo confirmed the theft of a Cloudflare API key, which was then used to inject ClickFix scripts into its own websites and JavaScript files embedded on customer sites.
The two reports align on the core details: the attack vector was a stolen API key, and the payload involved ClickFix scripts designed to distribute malware. The scale of the impact is consistent across both sources, with both citing the 100,000 figure. No significant discrepancies were noted between the reports.
This incident highlights the risk of third-party integrations and the potential for a single compromised credential to have a wide-reaching effect. The use of a Cloudflare worker, a common edge-computing tool, allowed the attackers to inject malicious content without directly breaching each individual customer site. The attack underscores the importance of monitoring API key usage and securing access to cloud infrastructure.
Sources · 2
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.