Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Security & Privacy

Brevo Supply Chain Attack Hits 100,000 Sites via Stolen API Key

A compromised Cloudflare API key allowed attackers to inject malicious scripts into Brevo's infrastructure, affecting a vast number of customer websites.

· 1 min read · 2 sources

A supply chain attack against Brevo, a marketing and email platform, has resulted in malicious code being injected into roughly 100,000 customer websites. According to SecurityWeek, the attackers leveraged a compromised API key to deploy a Cloudflare worker that injected malicious scripts. BleepingComputer adds that Brevo confirmed the theft of a Cloudflare API key, which was then used to inject ClickFix scripts into its own websites and JavaScript files embedded on customer sites.

The two reports align on the core details: the attack vector was a stolen API key, and the payload involved ClickFix scripts designed to distribute malware. The scale of the impact is consistent across both sources, with both citing the 100,000 figure. No significant discrepancies were noted between the reports.

This incident highlights the risk of third-party integrations and the potential for a single compromised credential to have a wide-reaching effect. The use of a Cloudflare worker, a common edge-computing tool, allowed the attackers to inject malicious content without directly breaching each individual customer site. The attack underscores the importance of monitoring API key usage and securing access to cloud infrastructure.

Sources · 2

  1. 01Brevo Supply Chain Attack Injects Malware Into 100,000 WebsitesSecurityWeek
  2. 02Brevo supply-chain attack injected ClickFix scripts on customer sitesBleepingComputer

More in Security & Privacy