ZeroHour
Victim

Brevo

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites

A Brevo supply chain compromise served malicious JavaScript to 100,000+ sites, installing WordPress backdoors and pushing ClickFix commands to visitors.

Sansec traced malicious JavaScript served through Brevo's cdn.brevo.com tracker loader, chat widget, and attacker sendibt1.com domains between 16:05:18 and 20:12:53 UTC on September 14, reaching more than 100,000 customer sites. For logged-in WordPress administrators the script attempted to install a plugin through the active admin session, assessed as a likely backdoor, while other visitors received a full-page ClickFix prompt that placed a command on the clipboard to paste and run. Sansec recorded 2,549 CSP violation reports across 12 sites, and evidence suggests attackers may have accessed Brevo's Cloudflare environment to enable DNS changes and altered responses, though the root cause is unconfirmed. Malicious hosts stopped resolving on September 15, but cached copies and already-compromised sites remain a concern.

Cyber Security Newsupdated · 6h agofirst · 7h agoData breach in the wild 5 sources

Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware

Attackers with Brevo DNS access injected malicious scripts serving ClickFix malware and WordPress backdoors to over 100,000 customer sites on 14 September 2026.

Brevo (formerly Sendinblue), an email marketing platform whose clients include eBay, Louis Vuitton, Michelin and Amnesty International, served injected JavaScript from sendibt1.com domains between 16:05 and 20:12 UTC on 14 September 2026, reaching over 100,000 customer sites and mailing lists. The f.js malware secretly installed a WordPress backdoor plugin from cdn10.sendibt1.com/p/wm.zip using logged-in admins' sessions and showed ClickFix overlays urging visitors to copy-paste and run commands. An SSL certificate for cdn.sendibt1.com created August 25 and attacker-created cdn* DNS records indicate write access to Brevo's Cloudflare DNS, likely via a single Cloudflare account compromise. Sansec recorded 2,549 CSP violation reports across 12 monitored sites; all malicious hosts stopped resolving on 15 September and Brevo's status page lists no incident.

Sansec (Magento / e-commerce security)updated · 6h agofirst · 2d agoMalware in the wild 5 sources