← Back to Feed
Brevo supply-chain attack injected ClickFix scripts on customer sites
September 17, 2026 · BleepingComputer · Severity: HIGH
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.
Key Takeaways
- A Brevo supply-chain attack injected ClickFix scripts on customer websites, compromising the marketing platform's infrastructure to distribute malware through trusted third-party integrations.
- Supply-chain attacks via marketing and email platforms pose significant risks as injected scripts can reach a wide audience through trusted communication channels.
- Organizations using third-party marketing platforms should implement content security policies and subresource integrity checks to detect unauthorized script injections.