Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
A Brevo supply chain compromise served malicious JavaScript to 100,000+ sites, installing WordPress backdoors and pushing ClickFix commands to visitors.
Sansec traced malicious JavaScript served through Brevo's cdn.brevo.com tracker loader, chat widget, and attacker sendibt1.com domains between 16:05:18 and 20:12:53 UTC on September 14, reaching more than 100,000 customer sites. For logged-in WordPress administrators the script attempted to install a plugin through the active admin session, assessed as a likely backdoor, while other visitors received a full-page ClickFix prompt that placed a command on the clipboard to paste and run. Sansec recorded 2,549 CSP violation reports across 12 sites, and evidence suggests attackers may have accessed Brevo's Cloudflare environment to enable DNS changes and altered responses, though the root cause is unconfirmed. Malicious hosts stopped resolving on September 15, but cached copies and already-compromised sites remain a concern.
- Malicious scripts served via Brevo CDN and chat widgets between 16:05 and 20:12 UTC, September 14.
- Injected script used live WordPress admin sessions to install a likely backdoor plugin.
- Visitors saw a fake verification prompt placing a command on the clipboard to run.
- Sansec logged 2,549 CSP violations across 12 sites; attacker domains went dark September 15.
- Attackers may have accessed Brevo's Cloudflare environment, enabling DNS changes; not yet confirmed.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | cdn10.sendibt1.com | frastructure, reported as NXDOMAIN from September 15 Domain cdn10.sendibt1.com Malicious loader infrastructure, reported as NXDOMAIN from |
| domain | cdn11.sendibt1.com | frastructure, reported as NXDOMAIN from September 15 Domain cdn11.sendibt1.com Malicious loader infrastructure, reported as NXDOMAIN from |
| domain | cdn2.sendibt1.com | frastructure, reported as NXDOMAIN from September 15 Domain cdn2.sendibt1.com Malicious loader infrastructure, reported as NXDOMAIN from |
| domain | cdn3.sendibt1.com | frastructure, reported as NXDOMAIN from September 15 Domain cdn3.sendibt1.com Malicious loader infrastructure, reported as NXDOMAIN from |
| domain | cdn4.sendibt1.com | frastructure, reported as NXDOMAIN from September 15 Domain cdn4.sendibt1.com Malicious loader infrastructure, reported as NXDOMAIN from |
| domain | cdn9.sendibt1.com | frastructure, reported as NXDOMAIN from September 15 Domain cdn9.sendibt1.com Malicious loader infrastructure, reported as NXDOMAIN from |
| domain | cdn.sendibt1.com | alled through an authenticated administrator session Domain cdn.sendibt1.com Malicious loader infrastructure, reported as NXDOMAIN from |
| domain | sendibt1.com | frastructure, reported as NXDOMAIN from September 15 Domain sendibt1.com Domain associated with attacker-controlled CDN records IP a |
| ipv4 | 104.21.77.104 | associated with attacker-controlled CDN records IP address 104.21.77.104 Address recorded for cdn.sendibt1.com IP address 172.246.24 |
| ipv4 | 172.246.243.65 | .21.77.104 Address recorded for cdn.sendibt1.com IP address 172.246.243.65 Address returned by sendibt1.com during the investigation S |
| sha256 | 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca | ad89550fbb221fb06782 Injected sdk-loader.js version SHA-256 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca Clean brevo-conversations.js version SHA-256 9b62c12bc5c7fe |
| sha256 | 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 | 5f3654042169fb2418aed09 Clean sdk-loader.js version SHA-256 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 Injected sdk-loader.js version SHA-256 f67d572d2d30407b3f47 |
| sha256 | 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 | ee3ab3f227ddca Clean brevo-conversations.js version SHA-256 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 Injected brevo-conversations.js version WordPress log artif |
| sha256 | f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 | f6ee500590099a432308 Injected sdk-loader.js version SHA-256 f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 Injected sdk-loader.js version SHA-256 26166cd87ff07e7a5031 |
| sha256 | fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 | s returned by sendibt1.com during the investigation SHA-256 fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 Clean sdk-loader.js version SHA-256 58a5c601c9df7ca21204355 |
Full article966 words · extracted from cybersecuritynews.com · click to collapse
A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators.
The activity reached more than 100,000 customer sites on September 14, according to the investigation. People who opened affected sites, chat features, sign-up forms, or email-linked unsubscribe pages could receive a fake verification prompt designed to make them run a command.
Researchers at Sansec identified the two-part operation after tracing altered scripts across Brevo-owned services and customer integrations. The first path targeted logged-in WordPress administrators, while the second used a ClickFix overlay against ordinary visitors.
Sansec said in a report shared with Cyber Security News (CSN) that the incident shows how one trusted web component can multiply an intrusion quickly.
Instead of breaking into each website separately, attackers can compromise a shared service and use its existing reach to place dangerous content in front of large audiences.
Brevo Supply Chain Attack
The malicious code was served between 16:05:18 and 20:12:53 UTC on September 14. It appeared on Brevo pages and in JavaScript used for a website tracker and chat widget, creating exposure wherever those components had been embedded.
When a visitor was already signed in to WordPress, the script attempted to install a plugin through that administrator’s active session.
Sansec could not recover the plugin, but assessed it as likely to be a backdoor, a risk echoed by reporting on trusted WordPress plugin backdoors that can quietly provide lasting access.
.webp)
For other visitors, the script displayed a full-page ClickFix prompt that posed as a human-verification step. It placed a command on the clipboard and instructed the user to paste and run it, turning a familiar web interaction into malware execution without exploiting a browser flaw.
Its monitoring recorded 2,549 content-security-policy violation reports across 12 sites during and after the activity window.
The malicious hosts stopped resolving on September 15, and the affected code was reported clean at origin, but cached copies and compromised sites remain a concern.
Although the initial disclosure described six hijacked customer accounts, Sansec’s findings point to a broader second-stage event affecting shared delivery infrastructure.
That distinction matters because an attack on a hosted asset can affect sites that never had their own account credentials stolen.
ClickFix Exposure and Response
ClickFix relies on persuasion rather than a silent download. Its fake browser check asks people to carry out the final step themselves, a pattern also seen in recent ClickFix malware campaigns that use convincing prompts to turn clipboard activity into an initial foothold on a device.
Site owners that used the affected tracker, chat widget, or hosted form should review web-server logs for the WordPress upload and activation requests listed below.
They should also inspect plugins installed or activated on September 14 and compare the files on disk with the administrator console, because a malicious plugin may hide from the normal list.
Visitors who followed the verification prompt and executed its command should run a full antivirus scan promptly and report any suspicious device behavior.
Organizations should remind staff and customers that legitimate websites do not require users to open a terminal, Run dialog, or command prompt to pass a security check, as fake verification attack guidance makes clear.
Security teams should preserve relevant logs before normal retention removes them, reset privileged accounts where justified, and look for unfamiliar files or changes.
Monitoring third-party JavaScript and limiting administrator sessions can reduce the chance that a single supplier compromise becomes a wider site breach.
The available evidence suggests the attackers may have gained access to Brevo’s Cloudflare environment, enabling both DNS changes and altered responses across related domains.
That remains an assessment, not a confirmed root cause, but it illustrates why third-party scripts deserve close monitoring, restricted administrative access, and rapid integrity checks after a supplier incident.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Modified JavaScript URL | https://cdn.brevo.com/js/sdk-loader.js | Affected tracker loader file |
| Modified JavaScript URL | https://cdn.brevo.com/js/brevo-conversations.js | Chat-widget JavaScript asset referenced in the investigation |
| Modified JavaScript URL | https://conversations-widget.brevo.com/brevo-conversations.js | Affected conversations-widget JavaScript file |
| Malicious script URL | https://cdn9.sendibt1.com/f.js | Injected malware script observed on affected Brevo pages |
| Malicious script URL | https://cdn2.sendibt1.com/f.js | Injected malware script loaded by altered assets |
| Malicious archive URL | https://cdn10.sendibt1.com/p/wm.zip | WordPress plugin archive reportedly installed through an authenticated administrator session |
| Domain | cdn.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| Domain | cdn2.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| Domain | cdn3.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| Domain | cdn4.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| Domain | cdn9.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| Domain | cdn10.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| Domain | cdn11.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| Domain | sendibt1.com | Domain associated with attacker-controlled CDN records |
| IP address | 104.21.77.104 | Address recorded for cdn.sendibt1.com |
| IP address | 172.246.243.65 | Address returned by sendibt1.com during the investigation |
| SHA-256 | fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 | Clean sdk-loader.js version |
| SHA-256 | 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 | Injected sdk-loader.js version |
| SHA-256 | f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 | Injected sdk-loader.js version |
| SHA-256 | 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca | Clean brevo-conversations.js version |
| SHA-256 | 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 | Injected brevo-conversations.js version |
| WordPress log artifact | /wp-admin/update.php?action=upload-plugin | POST request to review for unauthorized plugin upload activity |
| WordPress log artifact | /wp-admin/plugins.php?action=activate | GET request to review for suspicious plugin activation activity |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/brevo-supply-chain-attack/