BleepingComputerFriday · September 18, 2026FREE

Brevo supply-chain attack injected ClickFix scripts on customer sites

securitysupply-chainclickfixbrevo

BleepingComputer reported a supply-chain attack involving Brevo in which ClickFix scripts were injected on customer sites. According to the report, published on September 17, 2026, the incident is characterized as a supply-chain attack, and the injected content consisted of ClickFix scripts that appeared on sites belonging to Brevo customers. The source text does not specify how the scripts were injected, how many customer sites were affected, how long the activity lasted, or who was responsible. It also does not describe any response from Brevo, any remediation steps, or any confirmed impact on visitors to the affected sites. The report is limited to identifying the attack as a Brevo supply-chain incident and stating that ClickFix scripts were injected on customer sites.

// why it matters

The report indicates that scripts delivered through a vendor's supply chain can appear on customer sites, a distribution path developers relying on third-party services may need to account for.

Sources

Primary · BleepingComputer
▸ Read original at bleepingcomputer.com

Like this? Get the next digest.