Brevo says attackers compromise its infrastructure and inject malicious ClickFix scripts into websites and JavaScript assets embedded on customer sites. The incident involves a supply-chain method, where the malicious code is delivered through Brevo’s services rather than by targeting each customer site directly.

According to reporting, the attackers steal a Cloudflare API key and use it to deploy a Cloudflare worker. This worker then modifies content served to visitors by injecting the scripts intended to distribute malware. SecurityWeek reports the malware affects roughly 100,000 websites, while Brevo’s own disclosure and Bleeping Computer’s account describe the mechanism in terms of the script injection into Brevo-distributed site content.

Both outlets describe the key steps of the attack chain: theft of a Cloudflare API credential, deployment of a Cloudflare worker, and script injection into customer-facing web resources. The main differences are the emphasis and scale framing, with SecurityWeek highlighting the approximate number of impacted sites and other details focusing on Brevo’s confirmation of the Cloudflare key misuse and the ClickFix script payload.