confirmedhighSupply chainFirst reported Sep 17, 2026
Brevo: supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites. The injected scripts were used to distribute malware.
In the News
- Sep 17, 2026 · Bleeping ComputerBrevo supply-chain attack injected ClickFix scripts on customer sites