$ techbeacon▋
Malware

Brevo admits attackers hijacked Cloudflare key to inject malicious ClickFix scripts into client sites

Brevo admits attackers hijacked Cloudflare key to inject malicious ClickFix scripts into client sites

Brevo, the email‑marketing platform formerly known as Sendinblue, disclosed that a cyber‑crime group obtained a Cloudflare API key belonging to the company and used it to embed hostile ClickFix scripts across its own web assets and the JavaScript files that power customer integrations. The malicious code was designed to deliver malware to visitors of any site that relied on Brevo's hosted scripts.

The breach constitutes a classic supply‑chain attack, where a trusted third‑party service is compromised to reach a far larger audience. By compromising the API key, the attackers gained the ability to alter content served from Cloudflare’s edge network, effectively turning Brevo's legitimate resources into a distribution channel for malicious payloads.

According to the investigation, the stolen key enabled the perpetrators to modify JavaScript bundles that are automatically embedded in client pages for email sign‑ups, newsletters and transactional messages. The altered bundles included references to a script labeled "ClickFix," which, once executed in a visitor's browser, fetched and installed additional malware components without the user’s knowledge.

The intrusion came to light after security researchers at BleepingComputer observed the anomalous script in the wild and traced it back to Brevo’s domains. In response, Brevo confirmed the theft, revoked the compromised API credentials, and began a comprehensive cleanup of the affected files. The company also notified customers and urged them to review any custom code that interacts with Brevo's services.

While the full scope of the infection remains under assessment, Brevo warned that any website that had embedded the company's JavaScript during the intrusion window could have exposed its visitors to the malicious payload. Affected businesses have been advised to monitor for unusual activity, update any compromised scripts, and consider resetting authentication tokens linked to third‑party services.

The episode highlights the growing risk posed by supply‑chain vectors, especially when cloud‑based APIs are involved. Experts stress the importance of rotating API keys regularly, employing least‑privilege access controls, and implementing robust monitoring of content delivered through CDN networks. Brevo has pledged to strengthen its security posture and work closely with Cloudflare to prevent similar incidents in the future.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related