Attackers used a long-lived Cloudflare API key stored in Brevo's own source code to push malware through the marketing platform's…