Stolen API Key Let Attackers Push Fake Security Prompts Through Brevo to Customer Websites

Attackers stole a Cloudflare API key hardcoded in Brevo's source code and used it to inject ClickFix scripts into the company's own pages and into JavaScript components that customer websites embed, Brevo confirmed as reported by BleepingComputer.
ClickFix is a social-engineering technique in which a website shows visitors a fake browser or security warning, in this case a counterfeit Cloudflare verification page, and instructs them to run a command manually on Windows. The command delivers malware.
The stolen key had full account permissions and allowed the attackers to create a Cloudflare Worker, a piece of code that runs at the content-delivery edge and can rewrite web pages before they reach the browser. Brevo said the Worker "removed security headers such as Content-Security-Policy" so that "our origin servers and files remained unmodified and standard integrity checks did not detect the change." The exposure window ran from approximately 16:07 to 20:30 UTC on Sept. 14, roughly five hours.
Security firm Sansec, which first reported the incident, said the attack potentially reached up to 100,000 websites that embed Brevo's forms script, Conversations widget, or SDK loader: an estimate, not a confirmed count of compromised sites. The affected Brevo properties included brevo.com, sendinblue.com, and sibforms.com.
On WordPress sites where a logged-in administrator visited during the window, the injected script also attempted to install a malicious plugin that BleepingComputer identified on VirusTotal as a persistent backdoor and JavaScript loader. WordPress site operators who were logged in as administrator on Sept. 14 should audit plugins added that day. Brevo said its API, email delivery infrastructure, and customer account data were not affected.
The compromise is separate from a different Brevo incident disclosed Sept. 10, in which attackers hijacked customer accounts via a single sign-on flaw and launched phishing campaigns.
