Hackers used a malicious worker to inject scripts into more than 100,000 websites via the Brevo supply chain attack.