Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites

18 September 2026
Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites

A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators.

The activity reached more than 100,000 customer sites on September 14, according to the investigation. People who opened affected sites, chat features, sign-up forms, or email-linked unsubscribe pages could receive a fake verification prompt designed to make them run a command.

Researchers at Sansec identified the two-part operation after tracing altered scripts across Brevo-owned services and customer integrations. The first path targeted logged-in WordPress administrators, while the second used a ClickFix overlay against ordinary visitors.

Sansec said in a report shared with Cyber Security News (CSN) that the incident shows how one trusted web component can multiply an intrusion quickly.

Instead of breaking into each website separately, attackers can compromise a shared service and use its existing reach to place dangerous content in front of large audiences.

Brevo Supply Chain Attack

The malicious code was served between 16:05:18 and 20:12:53 UTC on September 14. It appeared on Brevo pages and in JavaScript used for a website tracker and chat widget, creating exposure wherever those components had been embedded.

When a visitor was already signed in to WordPress, the script attempted to install a plugin through that administrator’s active session.

Sansec could not recover the plugin, but assessed it as likely to be a backdoor, a risk echoed by reporting on trusted WordPress plugin backdoors that can quietly provide lasting access.

Attack chain (Source - Sansec)
Attack chain (Source – Sansec)

For other visitors, the script displayed a full-page ClickFix prompt that posed as a human-verification step. It placed a command on the clipboard and instructed the user to paste and run it, turning a familiar web interaction into malware execution without exploiting a browser flaw.

Its monitoring recorded 2,549 content-security-policy violation reports across 12 sites during and after the activity window.

The malicious hosts stopped resolving on September 15, and the affected code was reported clean at origin, but cached copies and compromised sites remain a concern.

Although the initial disclosure described six hijacked customer accounts, Sansec’s findings point to a broader second-stage event affecting shared delivery infrastructure.

That distinction matters because an attack on a hosted asset can affect sites that never had their own account credentials stolen.

ClickFix Exposure and Response

ClickFix relies on persuasion rather than a silent download. Its fake browser check asks people to carry out the final step themselves, a pattern also seen in recent ClickFix malware campaigns that use convincing prompts to turn clipboard activity into an initial foothold on a device.

Site owners that used the affected tracker, chat widget, or hosted form should review web-server logs for the WordPress upload and activation requests listed below.

They should also inspect plugins installed or activated on September 14 and compare the files on disk with the administrator console, because a malicious plugin may hide from the normal list.

Visitors who followed the verification prompt and executed its command should run a full antivirus scan promptly and report any suspicious device behavior.

Organizations should remind staff and customers that legitimate websites do not require users to open a terminal, Run dialog, or command prompt to pass a security check, as fake verification attack guidance makes clear.

Security teams should preserve relevant logs before normal retention removes them, reset privileged accounts where justified, and look for unfamiliar files or changes.

Monitoring third-party JavaScript and limiting administrator sessions can reduce the chance that a single supplier compromise becomes a wider site breach.

The available evidence suggests the attackers may have gained access to Brevo’s Cloudflare environment, enabling both DNS changes and altered responses across related domains.

That remains an assessment, not a confirmed root cause, but it illustrates why third-party scripts deserve close monitoring, restricted administrative access, and rapid integrity checks after a supplier incident.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Modified JavaScript URLhttps://cdn.brevo.com/js/sdk-loader.jsAffected tracker loader file
Modified JavaScript URLhttps://cdn.brevo.com/js/brevo-conversations.jsChat-widget JavaScript asset referenced in the investigation
Modified JavaScript URLhttps://conversations-widget.brevo.com/brevo-conversations.jsAffected conversations-widget JavaScript file
Malicious script URLhttps://cdn9.sendibt1.com/f.jsInjected malware script observed on affected Brevo pages
Malicious script URLhttps://cdn2.sendibt1.com/f.jsInjected malware script loaded by altered assets
Malicious archive URLhttps://cdn10.sendibt1.com/p/wm.zipWordPress plugin archive reportedly installed through an authenticated administrator session
Domaincdn.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
Domaincdn2.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
Domaincdn3.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
Domaincdn4.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
Domaincdn9.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
Domaincdn10.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
Domaincdn11.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
Domainsendibt1.comDomain associated with attacker-controlled CDN records
IP address104.21.77.104Address recorded for cdn.sendibt1.com
IP address172.246.243.65Address returned by sendibt1.com during the investigation
SHA-256fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09Clean sdk-loader.js version
SHA-25658a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308Injected sdk-loader.js version
SHA-256f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782Injected sdk-loader.js version
SHA-25626166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddcaClean brevo-conversations.js version
SHA-2569b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5Injected brevo-conversations.js version
WordPress log artifact/wp-admin/update.php?action=upload-pluginPOST request to review for unauthorized plugin upload activity
WordPress log artifact/wp-admin/plugins.php?action=activateGET request to review for suspicious plugin activation activity

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites appeared first on Cyber Security News.



>>More