Brevo: A Cloudflare Worker That Rewrote a Marketing Platform in Flight
On 14 September 2026, attackers used a long-lived Cloudflare API key to publish a malicious Cloudflare Worker in Brevo's account. The worker rewrote HTTP responses at the edge for roughly four hours, and because the origin was never touched, file hashes and conventional integrity monitoring showed nothing. Sansec estimated that more than 100,000 websites loaded the altered scripts.
How the key was used
Brevo stated that a Cloudflare API key with full account permissions had been hardcoded in application source code and was still valid. With it, the attacker created a Worker plus the routes and DNS records needed to bind it, and no alert was raised. The Worker modified responses for the Brevo site and for customer-embedded scripts, and removed security headers such as Content-Security-Policy while doing so. The worker also pulled an additional script from a domain under Brevo control, so no individual customer site had to be compromised.
The altered scripts were the widget and tracking files that thousands of sites include directly from Brevo, among them brevo-widget.js, sendinblue.js and brevo-embed.js.
Two payloads for two audiences
Ordinary visitors saw a fake verification overlay styled like a Cloudflare challenge. The page wrote a PowerShell command to the clipboard and instructed the visitor to press Win+R, paste and confirm. That ClickFix pattern moves code execution onto the visitor's workstation.
Logged-in WordPress administrators met a second payload. A plugin presented as Web Media Optimizer was installed through the active administrator session with no password prompt. It hid itself from the plugin list, persisted through the must-use plugin directory, and polled command and control. Sansec reported that the plugin appeared in VirusTotal, and the malicious behaviour was limited to requests from logged-in administrators so crawlers and scanners saw a clean page.
The earlier incident
Four days earlier, on 10 September 2026, Brevo disclosed that a SAML single sign-on flaw had exposed 138 customer accounts. Six of those accounts were used to send phishing mail, and contact data was exported from 43 accounts, including addresses associated with the Trezor hardware wallet. Brevo has not said whether the two events are related.
Cleanup and residual risk
Brevo revoked the key, removed the hardcoded credential from source, deleted the attacker-created records and purged the edge cache, and both Brevo and Cloudflare confirmed that malicious content was gone by 15 September 2026. One indicator needs care: sendibt1.com is a legitimate Brevo tracking domain, so blocking it breaks open and click tracking for customers who still use the platform. The attacker abused infrastructure that was already trusted.
For affected sites, the useful checks are access logs for plugin installation around 14 September, a comparison of files on disk against the plugin list in the WordPress admin, and a full scan of any workstation where an employee pasted a verification command.
References
- FreeBuf report on the Brevo supply-chain attack: https://www.freebuf.com/news/501898.html
- 51Testing summary with the exposure window and Brevo statement: http://www.51testing.com/?action-viewnews-itemid-7811516
- Sansec research index: https://sansec.io/research
Top comments (0)