Brevo — stolen Cloudflare API key turns its embedded widgets into a live malware dropper for 100,000+ customer sites
A long-lived Cloudflare API key with full account permissions was hardcoded in Brevo's application source; attackers used it to stand up a malicious Cloudflare Worker that rewrote content at the CDN edge for ~5.5 hours on September 14, hitting brevo.com itself plus the Brevo forms script, Conversations widget, and SDK loader that 100,000+ customer sites embed. Visitors got a fake Cloudflare verification page into a ClickFix clipboard-paste lure, and on WordPress sites the script fingerprinted logged-in admins and pushed a backdoored plugin ("Web Media Optimizer", staged from cdn10.sendibt1[.]com) that persists after the Worker is gone. This is the polyfill.io shape again — compromise one shared script, inherit every site that embeds it — except the blast radius here runs through a marketing/CDP vendor, not a CDN; if you or your customers embed Brevo's forms, chat widget, or SDK loader, check WordPress installs for the Web Media Optimizer plugin and block yelahaye[.]surf, boiseno[.]club, and cdn10.sendibt1[.]com now.