started · updated
Brevo supply-chain attack infects over 100,000 websites
A supply-chain attack targeting the French marketing platform Brevo has potentially affected over 100,000 websites. The incident involved two distinct phases of compromise.
Initially, attackers exploited a vulnerability in Brevo’s SAML SSO system, gaining access to 138 accounts, including one belonging to cryptocurrency hardware wallet manufacturer Trezor. While Brevo blocked this initial unauthorized access, attackers returned four days later using a compromised, highly privileged Cloudflare API key.
Using this key, the attackers deployed a malicious Cloudflare Worker to inject code at the CDN edge. This method allowed them to rewrite web responses and remove security headers, such as Content-Security-Policy, without modifying Brevo’s origin servers or files. This bypassed standard integrity checks and turned Brevo’s infrastructure into a malware distribution channel. The attack attempted to deliver “ClickFix” scripts, which prompt users to execute terminal commands, and sought to install unauthorized plugins on WordPress sites.