Brevo supply chain attack: stolen Cloudflare API key used to inject ClickFix malware and WordPress backdoor into 100,000+ sites
Attackers used a stolen, full-permission Cloudflare API key - first misused in late August 2026, per SecurityWeek - to inject ClickFix malware-delivery scripts and a persistent 'Web Media Optimizer' WordPress backdoor into 100,000+ Brevo customer sites for…
Brevo (formerly Sendinblue), an email marketing platform whose clients include eBay, Louis Vuitton, Michelin and Amnesty International, served injected JavaScript to more than 100,000 customer sites and its own pages on 14 September 2026; Sansec estimates 100,000+ affected websites and PublicWWW lists 114,371 pages referencing Brevo assets. Per SecurityWeek, the intrusion began on 10 September 2026 with a vulnerability in Brevo's SAML SSO handling that exposed 138 accounts, and the attackers then used a long-lived Cloudflare API key with full account permissions - first misused in late August 2026, per SecurityWeek - to deploy a malicious Cloudflare Worker that rewrote responses at the CDN edge and stripped Content-Security-Policy headers. Brevo confirmed, per BleepingComputer, that the key had been hardcoded in its source code and stolen; Sansec, GBHackers and Cyber Security News instead describe possible Cloudflare-environment access as unconfirmed, citing attacker-created cdn*.sendibt1.com DNS records and an SSL certificate for cdn.sendibt1.com created 25 August. The injected code loaded f.js from attacker-controlled sendibt1.com subdomains appended to legitimate Brevo resources and, per Cyber Security News, was also served through Brevo's cdn.brevo.com tracker loader and chat widget, affecting brevo.com, sendinblue.com, sibforms.com and customer-embedded Brevo scripts; SecurityWeek says the worker injected scripts into brevo.com, sibforms.com and three customer-embedded JavaScript files. Sources disagree on timing: Sansec, GBHackers and Cyber Security News observed 16:05:18-20:12:53 UTC (~4 hours), while Brevo, per BleepingComputer, put the window at 16:07-20:30 UTC (~5.5 hours). Visitors saw fake 'Cloudflare, verify you are human' pages using the ClickFix technique, instructing them to copy-paste and run a Windows command that was placed on the clipboard; where logged-in WordPress admins browsed, the injected code used their session to install a backdoor plugin named 'Web Media Optimizer' (BleepingComputer) from cdn10.sendibt1.com/p/wm.zip. The backdoor hides from the plugin list, persists in the must-use plugins directory, contacts attacker servers, and contains a hardcoded key to forge WordPress administrator sessions. Sansec recorded 2,549 CSP violation reports across 12 monitored sites. All malicious hosts stopped resolving on 15 September, though Cyber Security News warns that cached copies and already-compromised sites remain a concern, and…
- Brevo (formerly Sendinblue), an email marketing platform with clients including eBay, Louis Vuitton, Michelin and Amnesty International, served injected JavaScript to 100,000+ customer sites and its own pages on 14 September 2026;…
- Per SecurityWeek, attackers first breached Brevo on 10 September 2026 via a SAML SSO handling flaw, and the compromised long-lived Cloudflare API key with full account permissions was first misused in late August 2026.
- Brevo confirmed (per BleepingComputer) the full-permission Cloudflare API key had been hardcoded in source code and was stolen to create a malicious Cloudflare Worker that rewrote CDN edge responses and stripped Content-Security-Policy…
- Injection window: 16:05:18-20:12:53 UTC (~4 hours) per Sansec, GBHackers and Cyber Security News; Brevo, per BleepingComputer, put it at 16:07-20:30 UTC (~5.5 hours).
- Injected scripts loaded f.js from attacker-controlled sendibt1.com subdomains appended to legitimate Brevo resources, affecting brevo.com, sendinblue.com, sibforms.com and customer-embedded Brevo scripts; per Cyber Security News the code…
- Visitors saw fake 'Cloudflare, verify you are human' pages using the ClickFix technique, with a Windows command placed on the clipboard to paste and run.
- Where logged-in WordPress admins browsed, the script used their session to install a backdoor plugin from cdn10.sendibt1.com/p/wm.zip, named 'Web Media Optimizer' per BleepingComputer; it hides from the plugin list, persists in the…
- Sansec recorded 2,549 CSP violation reports across 12 monitored sites.
Coverage timelineoldest first · each row is one article
- · 2d agoBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)· 85
Attackers with Brevo DNS access injected malicious scripts serving ClickFix malware and WordPress backdoors to over 100,000 customer sites on 14 September 2026.
- · 21h agoBrevo supply-chain attack injected ClickFix scripts on customer sites
BleepingComputer· 80
Attackers used a stolen Cloudflare API key to inject ClickFix malware-delivery scripts into Brevo sites and customer-embedded scripts for five hours.
- · 9h agoHackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites
GBHackers· 82
Attackers compromised Brevo-hosted JavaScript to deliver a WordPress backdoor and ClickFix payloads across 100,000+ websites, exposing visitors and admins.
- · 6h agoBrevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
Cyber Security News· 74
A Brevo supply chain compromise served malicious JavaScript to 100,000+ sites, installing WordPress backdoors and pushing ClickFix commands to visitors.
- · 5h agoBrevo Supply Chain Attack Injects Malware Into 100,000 Websites
SecurityWeek· 78
Attackers breached Brevo, hijacked a Cloudflare API key, and injected ClickFix malware scripts served to visitors of 100,000+ websites including Trezor.