← Back to Feed

Brevo supply-chain attack injected ClickFix scripts on customer sites

September 17, 2026 · BleepingComputer · Severity: HIGH

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.

Key Takeaways

  • A Brevo supply-chain attack injected ClickFix scripts on customer websites, compromising the marketing platform's infrastructure to distribute malware through trusted third-party integrations.
  • Supply-chain attacks via marketing and email platforms pose significant risks as injected scripts can reach a wide audience through trusted communication channels.
  • Organizations using third-party marketing platforms should implement content security policies and subresource integrity checks to detect unauthorized script injections.
☕ Buy a Coffee