Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
A Brevo supply chain compromise served malicious JavaScript to 100,000+ sites, installing WordPress backdoors and pushing ClickFix commands to visitors.
Sansec traced malicious JavaScript served through Brevo's cdn.brevo.com tracker loader, chat widget, and attacker sendibt1.com domains between 16:05:18 and 20:12:53 UTC on September 14, reaching more than 100,000 customer sites. For logged-in WordPress administrators the script attempted to install a plugin through the active admin session, assessed as a likely backdoor, while other visitors received a full-page ClickFix prompt that placed a command on the clipboard to paste and run. Sansec recorded 2,549 CSP violation reports across 12 sites, and evidence suggests attackers may have accessed Brevo's Cloudflare environment to enable DNS changes and altered responses, though the root cause is unconfirmed. Malicious hosts stopped resolving on September 15, but cached copies and already-compromised sites remain a concern.