news.mlab.sh
Back to the feed
supply-chain

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

High
Summary

Brevo, a customer engagement platform, suffered a supply chain attack resulting in malicious code injected into over 100,000 websites. The attackers exploited a vulnerability to gain access to accounts and then used a compromised API key to deploy a worker that served a fake ‘Cloudflare, verify you are human’ page, tricking users into running malware. The incident highlights the risks associated with supply chain attacks and the importance of diligent monitoring of customer websites.

Brevo, a customer engagement platform, was recently targeted by a sophisticated supply chain attack that impacted over 100,000 websites. The initial breach occurred on September 10th, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor. The attackers then leveraged this access to send phishing emails from six of the compromised accounts and exported the contacts of 43 accounts, as detailed in Brevo’s incident notice.

On September 14th, the attackers returned, utilizing a compromised long-lived Cloudflare API key to deploy a worker. This worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites. The script presented selected visitors with a fake ‘Cloudflare, verify you are human’ page, instructing them to paste and run a command on their computer – a social-engineering technique known as ClickFix.

On WordPress websites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator. The malicious worker remained active for approximately five and a half hours before Brevo removed it and revoked the compromised API key and credentials. According to cybersecurity firm Sansec, the malware served for roughly four hours, and more than 100,000 websites were likely impacted.

Brevo recommends that all sites using Brevo be reviewed for potential compromise. Administrators should check for unauthorized plugin installations, and site visitors should check their machines for malware if they were served the fake verification pages. "Brevo is no longer serving malicious code. However, your WordPress site may have been backdoored, and your customers may have fallen for the ClickFix scam," Sansec notes.

Read the full article at SecurityWeek