Brevo Confirms Supply-Chain Attack via Cloudflare Worker, Scripts Spread ClickFix Malware
A compromised Cloudflare API key allowed an attacker to inject malicious code into Brevo pages and embedded scripts used on customer websites. The incident lasted approximately 5.5 hours.

Brevo ClickFix attack affected the marketing platform’s pages and embedded JavaScript elements used on its customers’ websites. Brevo confirmed that the attacker obtained a Cloudflare API key with full permissions and created a malicious Cloudflare Worker. At the CDN edge, it modified content to show selected visitors a fake Cloudflare prompt and trick them into running a Windows command that downloaded malware.
According to the company’s post-mortem, the main part of the incident lasted from 15:01 to 20:30 UTC on September 14, 2026. From 16:07 UTC, the malicious content also spread to three embedded JavaScript files. Brevo states that the affected scripts are now safe after the attacker’s infrastructure was removed.
The Brevo ClickFix attack exploited trusted embedded scripts
The attacker did not breach Brevo’s source servers. Instead, they used the compromised key’s permissions to create a Worker and routes that modified responses at the Cloudflare network layer. This made it possible to inject a malicious script directly into Brevo pages and into elements loaded on external websites.
The affected components included Brevo Forms, Brevo Conversations, and the Brevo SDK loader. These are scripts that website operators embed, for example, for forms or communication widgets. A visitor to a customer website could therefore receive modified content even though the operator’s own website did not necessarily come under direct attack.
ClickFix is a social engineering technique. In this case, the fake prompt imitated a Cloudflare check and instructed visitors to run a command in Windows. The command then downloaded malware. Brevo did not state how many people followed the prompt or how many devices were subsequently compromised.
Attempted silent plugin installation on WordPress
On WordPress websites with the affected widget, the malicious script exhibited additional behavior. If the visitor was logged in as a WordPress administrator, the code attempted to silently install and activate a plugin. However, the available confirmed information does not show how many WordPress installations this attempt succeeded on.
External security firm Sansec estimates that more than 100,000 websites could potentially have been involved. However, this is not a Brevo-confirmed number of affected websites or victims. Brevo also acknowledged possible misuse of the key as early as late August, but found no evidence of a malicious injection before September 14.
Brevo revoked the keys and cleared the CDN cache
The company removed the malicious Worker and its routes, revoked the compromised API key and credentials created through that key. It also deleted hostnames created by the attacker and cleared Cloudflare’s edge cache. These steps were intended to remove modified content from the distribution layer.
According to Brevo, the incident did not affect app.brevo.com, the Brevo API, email delivery, or customer data stored in Brevo. The confirmed scope of the issue concerns content distributed through pages and embedded scripts during the stated time window.
The case is an example of an actively exploited supply-chain attack: a single privileged access key provided a path to trusted scripts loaded on third-party websites. It also demonstrates the difference between content controlled on the origin server and content modified at the CDN edge.
What website operators should monitor
Operators who used Brevo Forms, Brevo Conversations, or the Brevo SDK loader during the incident should review security logs for that period, especially unusual activity involving WordPress administrator accounts and unknown plugins. On devices where a user followed instructions from the fake Cloudflare prompt, addressing a possible malware infection is relevant.
Brevo announced measures including short-lived tokens with narrowly defined permissions, centralized secret storage, audit alerts, and external reviews of embedded scripts. It remains important to monitor whether the company publishes a more precise number of affected websites, visitors, or confirmed compromised WordPress installations.
Sources
- Brevo Status – Security Incident – ClickFix write-up – Primarily confirms the compromised Cloudflare API key, timeline, affected areas, ClickFix mechanism, attempted WordPress plugin installation, and remediation steps.
- Sansec – Brevo supply chain attack – Independently documents the injection into embedded scripts, timing observations, indicators of compromise, and an estimated scope of more than 100,000 websites.
- BleepingComputer – Brevo supply-chain attack injected ClickFix scripts on customer sites – Corroborates Brevo’s post-mortem and provides additional technical findings about the analyzed malicious WordPress plugin.
Verified and updated: September 18, 2026 06:23



