Brevo Supply-Chain Attack Injected Malicious Scripts on Customer Sites

Attackers compromised Brevo by stealing a Cloudflare API key and injecting malicious scripts into Brevo and its customers' websites, resulting in malware distribution via a supply-chain attack.

Why it matters

Compromise of API keys in supply-chain attacks enables threat actors to inject malicious code into trusted customer environments, elevating risks to data integrity and user safety.

SOC impact

Monitor network and web traffic for anomalies related to ClickFix script activity and unauthorized API usage. Assess websites and embedded scripts for unauthorized modifications originating from Brevo or linked assets. Prioritize investigation of alerts involving Cloudflare API key misuse and suspicious script injections.

Recommended actions

  1. Identify web assets utilizing Brevo and ClickFix scripts
  2. Audit usage of Cloudflare API keys within the environment
  3. Analyze web traffic for unauthorized script injection indicators
  4. Review endpoint and network telemetry for malware activity linked to the compromise
  5. Correlate alerts involving third-party JavaScript modifications

Executive Summary

Attackers gained unauthorized access to a Cloudflare API key used by Brevo, a service provider, allowing them to inject malicious ClickFix scripts into both Brevo’s own websites and the JavaScript embedded on customer sites. This supply-chain compromise facilitated the distribution of malware across multiple downstream targets.

The incident underscores the operational threat posed by the misuse of trusted credentials like API keys within software supply chains. Security teams should emphasize monitoring for irregularities in third-party script behavior and validate the integrity of web assets relying on Brevo and Cloudflare services. Rapid detection of unauthorized script injections can help mitigate further impact from this type of attack.

SOC Impact

Monitor network and web traffic for anomalies related to ClickFix script activity and unauthorized API usage. Assess websites and embedded scripts for unauthorized modifications originating from Brevo or linked assets. Prioritize investigation of alerts involving Cloudflare API key misuse and suspicious script injections.

Detection and Monitoring Focus

  • Identify web assets utilizing Brevo and ClickFix scripts
  • Audit usage of Cloudflare API keys within the environment
  • Analyze web traffic for unauthorized script injection indicators
  • Review endpoint and network telemetry for malware activity linked to the compromise
  • Correlate alerts involving third-party JavaScript modifications

Why It Matters

Compromise of API keys in supply-chain attacks enables threat actors to inject malicious code into trusted customer environments, elevating risks to data integrity and user safety.

Source