A forgotten Cloudflare key turned 100,000 sites into a malware channel

Attackers used a long-lived Cloudflare API key stored in Brevo's own source code to push malware through the marketing platform's scripts to more than 100,000 websites.

CSBadmin
2 Min Read

A script tag is a trust decision. Thousands of websites made that decision with Brevo, and on September 14 the marketing platform handed malware to their visitors.

The return came four days after Brevo shut down an earlier intrusion, and it arrived without needing a password. What the attackers needed was sitting in Brevo’s application source code: a long-lived Cloudflare API key with full account permissions. They used it to publish a Cloudflare Worker that rewrote responses at the edge.

Brevo’s origin servers never changed, so file hashes and standard integrity monitoring found nothing. The Worker also stripped security headers, Content-Security-Policy among them, on the way through.

Visitors met a fake “verify you are human” overlay that asked them to paste a command into their own terminal, the ClickFix pattern. WordPress administrators signed in while browsing their own sites faced worse: the injected script tried to install a plugin through the active session. On VirusTotal that plugin surfaced as “Web Media Optimizer.” It can hide itself from the admin plugin list and survive in the must-use plugins folder, per BleepingComputer.

Sansec estimates more than 100,000 sites were served the payload. Brevo puts the Worker’s life at roughly five and a half hours and says the key was first misused in late August.

The cleanup advice is blunt. Review any site embedding Brevo for plugins nobody installed, and treat machines that saw the verification prompt as compromised.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.