$ techbeacon▋
Malware

Hackers Exploit Brevo API to Plant Malware on Over 100,000 Sites via Cloudflare Workers

A coordinated supply‑chain breach of the Brevo email‑marketing service has resulted in malicious code being delivered to more than 100,000 websites, security researchers reported. The intrusion was traced to a compromised API key that allowed attackers to create a Cloudflare worker, a serverless script that runs at the edge of the network, which then injected harmful JavaScript into the pages of vulnerable sites.

Brevo, formerly known as Sendinblue, provides a suite of marketing tools that many small‑ and medium‑sized businesses integrate into their own web properties. By hijacking an API credential, the threat actors were able to push a Cloudflare worker into the platform’s infrastructure without triggering standard alerts. The worker silently appended the malicious payload to every page served through Brevo’s integration, turning otherwise legitimate sites into vectors for further exploitation.

The attack highlights the growing risk of supply‑chain vulnerabilities, where a single compromised component can cascade across thousands of downstream users. Cloudflare workers, while offering performance benefits, also present a powerful attack surface when misused, as they execute code close to the end user and can bypass many traditional security controls. Security analysts note that the use of a legitimate service to host the malicious script makes detection especially challenging for site owners who rely on third‑party integrations.

SecurityWeek, which first broke the story, emphasized that the breach appears to have been systematic rather than opportunistic, given the scale of the injection. While the exact motive remains unclear, the malicious scripts are believed to be designed for data theft and further propagation, typical of campaigns that aim to harvest credentials or install additional malware on visitor browsers. The affected websites range across various industries, underscoring how a single compromised vendor can impact a broad digital ecosystem.

Brevo has responded by revoking the compromised API key, disabling the rogue Cloudflare worker, and initiating a full audit of its developer environment. The company is urging customers to rotate any API credentials and to monitor web traffic for unexpected script injections. Cybersecurity experts recommend that organizations employing third‑party services adopt strict key management practices, enforce least‑privilege access, and regularly scan for anomalous outbound requests. As investigations continue, the incident serves as a stark reminder that supply‑chain defenses must evolve alongside the increasing reliance on cloud‑based, serverless technologies.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related