Brevo Cloudflare Worker Injected ClickFix Malware Into 100k+ Sites After SAML Breach
Brevo suffered a supply-chain compromise via SAML then a stolen Cloudflare key, injecting ClickFix and WordPress backdoors across over 100,000 sites. Evidence points to five-hour active window and late-August key misuse. Operators face ongoing risk from embedded scripts and admin-targeted plugins.
Brevo confirmed initial access on September 10 via a SAML SSO flaw that exposed 138 accounts, including Trezor. Attackers exported contacts and sent phishing from six accounts. After initial eviction, they returned using a Cloudflare key first misused in late August to push malicious scripts into brevo.com, sibforms.com, and three customer-embedded JavaScript files. Sansec telemetry showed the worker active for roughly four hours and estimated impact above 100,000 sites. On WordPress instances the script attempted to install a plugin when an administrator was detected. Brevo revoked the key and removed the worker; no earlier customer-page injections were found. The pattern matches prior third-party script compromises where long-lived API tokens and embedded widgets create persistent reach into downstream sites. ClickFix delivery targeting logged-in admins increases the chance of secondary persistence beyond the initial five-hour window. Site operators must audit for unauthorized plugins and check browser histories for pasted commands. Brevo customers should rotate all API keys and review SAML configurations. Expect similar worker-based injections as Cloudflare adoption grows without short-lived credential enforcement.
Sansec: At least 200 additional WordPress sites will disclose unauthorized Brevo-related plugins by October 31.
Sources (2)
- [1]Primary Source(https://www.brevo.com/blog/post-mortem-security-incident/)
- [2]Supporting Source(https://sansec.io/research/brevo-malware-campaign)