NewsTradingSentimentCalendarCommunityBriefing
Tech

Marketing Tool Brevo Breached to Spread Malware via Customer Sites

By Tech Desk · 2026-09-19 · 2 min read
A digital shield with a crack running through it, symbolizing a breach in security defenses.
Illustration: Tradingbird

A security lapse at Brevo allowed attackers to hijack its content delivery network, injecting malicious scripts into the websites of potentially 100,000 customers.

Brevo, a major provider of digital marketing tools, confirmed that its systems were compromised in a supply-chain attack that affected customer websites. Attackers stole a critical security key and used it to modify the company's content delivery network. This allowed them to inject malicious scripts into the JavaScript files that Brevo embeds on client sites.

The incident occurred on September 14, lasting for approximately five and a half hours. During this window, visitors to affected Brevo pages and sites using its widgets encountered fake verification prompts. These prompts urged users to run specific commands, a tactic known as ClickFix, designed to trick individuals into installing malware on their own devices.

Stolen key enabled edge manipulation

The root cause was a long-lived API key with full account permissions that had been hardcoded into application source code. According to BleepingComputer, this oversight allowed attackers to create malicious Cloudflare Workers without triggering standard alerts. Because the modification happened at the network edge, the original files on Brevo's servers remained unchanged, bypassing typical integrity checks.

The compromised key may have been accessible to attackers as early as late August, though no prior malicious activity was detected. Brevo identified the exposure window between 16:07 and 20:30 UTC. Upon discovery, the company revoked the key, removed the malicious workers, and purged its edge caches to stop the distribution of harmful scripts.

Malicious plugin targets WordPress admins

Security firm Sansec reported that up to 100,000 websites using Brevo components could have been impacted. On WordPress sites, the injected script checked if the visitor was an administrator. If so, it attempted to upload a malicious plugin disguised as a media optimizer. This plugin acts as a persistent backdoor, hiding itself from the standard plugin list and copying itself into the must-use plugins directory.

Once installed, the plugin periodically contacts attacker-controlled servers to fetch new instructions. It also contains a hardcoded authentication key that allows attackers to generate valid administrator login sessions without needing a password. This creates a significant risk for site owners, as the compromise grants full control over the website's administrative functions.

Customers advised to audit sites

While Brevo stated that customer account data and email infrastructure were not affected, the risk to third-party websites remains high. Site administrators are urged to check for unauthorized plugins and review access logs for any suspicious activity during the specified time frame. The trade-off for using third-party marketing widgets is that a breach in the provider's infrastructure can directly compromise the security of the client's digital presence.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories