Interestana
Home/News/Brevo Supply-Chain Attack Injected Malware Via ClickFix Scripts
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Brevo Supply-Chain Attack Injected Malware Via ClickFix Scripts

Brevo confirmed on May 15, 2024, that a supply-chain attack resulted in the injection of malicious ClickFix scripts onto its websites and JavaScript files embedded on customer sites. Attackers successfully stole a Cloudflare API key, which they then leveraged to gain unauthorized access and deploy the harmful scripts. This breach allowed for the distribution of malware to Brevo's customers and their end-users. The company stated that the compromised API key was immediately revoked upon detection, and it has since implemented additional security measures to prevent future occurrences.

Brevo, formerly known as Sendinblue, is a customer relationship management (CRM) platform that offers a suite of tools for businesses, including email marketing, SMS marketing, chat, and a CRM system. The platform serves over 500,000 businesses globally, making the scope of this supply-chain attack potentially significant. The ClickFix scripts, identified as the vector for malware distribution, are designed to exploit vulnerabilities or trick users into downloading malicious software. The exact nature and extent of the malware distributed have not been fully disclosed by Brevo, but the company has initiated an investigation to assess the full impact on its customers.

This incident highlights the persistent threat of supply-chain attacks, where attackers target a trusted software provider to gain access to its downstream customers. By compromising Brevo's infrastructure, the attackers bypassed direct security measures that individual customers might have in place. Cloudflare, a major provider of web infrastructure and security services, was involved as its API key was compromised, underscoring the importance of securing access credentials. Brevo has committed to transparency and is working with affected customers to help them mitigate any potential damage. The company is also reviewing its internal security protocols and its relationship with third-party service providers to strengthen its defenses against sophisticated cyber threats.

Brevo's response included notifying its customers about the incident and providing guidance on how to check their websites for any signs of compromise. The company's security team worked around the clock to identify and remove the malicious scripts and to restore the integrity of its platform and customer sites. The investigation is ongoing, and Brevo has pledged to provide further updates as more information becomes available. This event serves as a stark reminder for businesses to maintain robust security practices, including regular audits of API keys, stringent access controls, and continuous monitoring for suspicious activities across their digital assets.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next