Desk live·
ForensicPost
Cloud/Supply chain/File 26-0914

Brevo’s Hardcoded Cloudflare Key Let One Worker Rewrite Scripts on 100,000 Customer Sites

A long-lived API key with full account permissions sat in the email platform’s source code. For five and a half hours on 14 September, an edge Worker stripped security headers and injected a fake verification page and a WordPress backdoor into every page that loaded Brevo’s widgets.

Constructed geometry · not a chart of case data
JurisdictionFranceParisthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBrevo customer websites
ActorUnattributed
S. Rosler11 min readConfidence: high4 sources reviewed

At 14:23 UTC on 14 September 2026 an attacker holding a Cloudflare API key belonging to Brevo, the Paris email-marketing and CRM platform formerly called Sendinblue, created a hostname on a Brevo-owned domain. By 15:01 a Cloudflare Worker was rewriting responses on brevo.com. At 16:07 it was updated to target the three scripts Brevo customers embed on their own sites: the forms script, the chat widget and the SDK loader. The Worker was removed and the key revoked at 20:30. Brevo’s write-up puts the impact at five hours and 29 minutes.

The key, Brevo said, was long-lived, carried full account permissions and was stored in application source code. It let the attacker create Workers, routes and DNS records across every Brevo zone without an alert firing. Sansec found a certificate for the attacker’s hostname issued on 25 August, and Brevo told SecurityWeek the key was first misused in late August.

What The Injected Script Did

The Worker stripped Content-Security-Policy headers and injected JavaScript. For ordinary visitors it displayed a fake Cloudflare human-verification page instructing them to press Win+R and paste a command, the ClickFix technique, which downloaded Windows malware. For visitors who were logged-in WordPress administrators it silently fetched and activated a plugin named Web Media Optimizer that hid itself from the plugin list, copied itself to the must-use directory and carried a hardcoded key allowing an attacker to mint an admin session without a password.

A Hundred Thousand Sites, By Footprint

The reach figure of up to 100,000 websites is Sansec’s estimate from counts of sites embedding Brevo widgets, repeated by BleepingComputer and SecurityWeek. Brevo published no site count. It is a measure of exposure, not of infection: the number of visitors who ran the command and the number of WordPress sites that received the plugin are unknown. Brevo states its application, API, email infrastructure and account data were not affected, which is consistent with an attack that never entered them and did not need to.

The Secret In The Repository

The corpus filed at 25-0826 what a single exposed token can reach at Cloudflare, and at 25-0818 what one integration reaches across 700 customer environments. This file combines them. One credential in source code, with permissions for everything, gave an attacker the platform’s edge, and the edge is where every customer’s page is assembled. Brevo’s remediation list says what was missing: a vault with rotation, alerts on Worker and DNS changes, and integrity checks on the versioned assets its customers load. Four days earlier the company had disclosed a separate SSO flaw used to hijack 138 accounts; whether the two share an actor was not said.

How we reported this

Compiled from Brevo’s incident write-up, Sansec’s analysis and contemporaneous reporting, listed below. The timeline is Brevo’s in UTC; Sansec’s window differs by minutes. The 100,000-site figure is a footprint estimate and is labelled as one. No attribution exists. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Incident write-up, 14 September 2026Brevo
  2. Brevo supply chain attack hits 100k+ sites with Wordpress backdoorsSansec
  3. Brevo supply-chain attack injected ClickFix scripts on customer sitesBleepingComputer
  4. Brevo Supply Chain Attack Injects Malware Into 100,000 WebsitesSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary