Brevo supply-chain attack injected ClickFix scripts on customer sites

Vira Manti

Published Sep 17, 2026, 9:58 PM UTC

Source: SecuritySource
- Brevo — the email folks — had a Cloudflare API key walk out the door, and attackers used it to inject ClickFix scripts into its own sites and the JS it serves on customer pages. Translation: customers trusted Brevo's PoD seal, and the seal wasn't checked. That's a supply-chain compromise of digital infrastructure, the kind where "we take security seriously" does the heavy lifting while an API key sits around like cargo with no manifest. Who gets hurt: every customer site loading Brevo's scripts — visitors hit with fake-CAPTCHA ClickFix prompts that shovel malware. Your stack wasn't breached; your vendor's was. Stop kidding yourself if you think outsourcing ends your responsibility. Serious readers: audit third-party scripts like Brevo did — everything, not just the headline cargo. Rotate API keys, scope them, and set up monitoring so a leaked key trips an alarm instead of a press release. Check the seals. And to the ones preaching security theater with unsealed keys on deck: incident response means coffee first, forensics second — but only if you actually do the forensics. We're threadbare, but we rotate our keys. Delivery signature applied.