ZeroHour
Story · 5 sources · 5 articlesfirst updated ()1

Brevo supply chain attack: stolen Cloudflare API key used to inject ClickFix malware and WordPress backdoor into 100,000+ sites

highData breachexploited in the wildimportance 85
What's new: SecurityWeek (18 September) identifies the 10 September SAML SSO handling flaw as the attackers' initial access, directly linking the two Brevo incidents that other sources described as separate. SecurityWeek also reports the compromised Cloudflare API key was first misused in late August 2026, and confirms crypto storage provider Trezor was among the 138 accounts accessed in the 10 September SSO…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Attackers used a stolen, full-permission Cloudflare API key - first misused in late August 2026, per SecurityWeek - to inject ClickFix malware-delivery scripts and a persistent 'Web Media Optimizer' WordPress backdoor into 100,000+ Brevo customer sites for…

Brevo (formerly Sendinblue), an email marketing platform whose clients include eBay, Louis Vuitton, Michelin and Amnesty International, served injected JavaScript to more than 100,000 customer sites and its own pages on 14 September 2026; Sansec estimates 100,000+ affected websites and PublicWWW lists 114,371 pages referencing Brevo assets. Per SecurityWeek, the intrusion began on 10 September 2026 with a vulnerability in Brevo's SAML SSO handling that exposed 138 accounts, and the attackers then used a long-lived Cloudflare API key with full account permissions - first misused in late August 2026, per SecurityWeek - to deploy a malicious Cloudflare Worker that rewrote responses at the CDN edge and stripped Content-Security-Policy headers. Brevo confirmed, per BleepingComputer, that the key had been hardcoded in its source code and stolen; Sansec, GBHackers and Cyber Security News instead describe possible Cloudflare-environment access as unconfirmed, citing attacker-created cdn*.sendibt1.com DNS records and an SSL certificate for cdn.sendibt1.com created 25 August. The injected code loaded f.js from attacker-controlled sendibt1.com subdomains appended to legitimate Brevo resources and, per Cyber Security News, was also served through Brevo's cdn.brevo.com tracker loader and chat widget, affecting brevo.com, sendinblue.com, sibforms.com and customer-embedded Brevo scripts; SecurityWeek says the worker injected scripts into brevo.com, sibforms.com and three customer-embedded JavaScript files. Sources disagree on timing: Sansec, GBHackers and Cyber Security News observed 16:05:18-20:12:53 UTC (~4 hours), while Brevo, per BleepingComputer, put the window at 16:07-20:30 UTC (~5.5 hours). Visitors saw fake 'Cloudflare, verify you are human' pages using the ClickFix technique, instructing them to copy-paste and run a Windows command that was placed on the clipboard; where logged-in WordPress admins browsed, the injected code used their session to install a backdoor plugin named 'Web Media Optimizer' (BleepingComputer) from cdn10.sendibt1.com/p/wm.zip. The backdoor hides from the plugin list, persists in the must-use plugins directory, contacts attacker servers, and contains a hardcoded key to forge WordPress administrator sessions. Sansec recorded 2,549 CSP violation reports across 12 monitored sites. All malicious hosts stopped resolving on 15 September, though Cyber Security News warns that cached copies and already-compromised sites remain a concern, and…

  • Brevo (formerly Sendinblue), an email marketing platform with clients including eBay, Louis Vuitton, Michelin and Amnesty International, served injected JavaScript to 100,000+ customer sites and its own pages on 14 September 2026;…
  • Per SecurityWeek, attackers first breached Brevo on 10 September 2026 via a SAML SSO handling flaw, and the compromised long-lived Cloudflare API key with full account permissions was first misused in late August 2026.
  • Brevo confirmed (per BleepingComputer) the full-permission Cloudflare API key had been hardcoded in source code and was stolen to create a malicious Cloudflare Worker that rewrote CDN edge responses and stripped Content-Security-Policy…
  • Injection window: 16:05:18-20:12:53 UTC (~4 hours) per Sansec, GBHackers and Cyber Security News; Brevo, per BleepingComputer, put it at 16:07-20:30 UTC (~5.5 hours).
  • Injected scripts loaded f.js from attacker-controlled sendibt1.com subdomains appended to legitimate Brevo resources, affecting brevo.com, sendinblue.com, sibforms.com and customer-embedded Brevo scripts; per Cyber Security News the code…
  • Visitors saw fake 'Cloudflare, verify you are human' pages using the ClickFix technique, with a Windows command placed on the clipboard to paste and run.
  • Where logged-in WordPress admins browsed, the script used their session to install a backdoor plugin from cdn10.sendibt1.com/p/wm.zip, named 'Web Media Optimizer' per BleepingComputer; it hides from the plugin list, persists in the…
  • Sansec recorded 2,549 CSP violation reports across 12 monitored sites.

Coverage timeline

  1. · 2d ago
    Sansec (Magento / e-commerce security)· 85
    Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware

    Attackers with Brevo DNS access injected malicious scripts serving ClickFix malware and WordPress backdoors to over 100,000 customer sites on 14 September 2026.

  2. · 21h ago
    BleepingComputer· 80
    Brevo supply-chain attack injected ClickFix scripts on customer sites

    Attackers used a stolen Cloudflare API key to inject ClickFix malware-delivery scripts into Brevo sites and customer-embedded scripts for five hours.

  3. · 9h ago
    GBHackers· 82
    Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

    Attackers compromised Brevo-hosted JavaScript to deliver a WordPress backdoor and ClickFix payloads across 100,000+ websites, exposing visitors and admins.

  4. · 6h ago
    Cyber Security News· 74
    Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites

    A Brevo supply chain compromise served malicious JavaScript to 100,000+ sites, installing WordPress backdoors and pushing ClickFix commands to visitors.

  5. · 5h ago
    SecurityWeek· 78
    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    Attackers breached Brevo, hijacked a Cloudflare API key, and injected ClickFix malware scripts served to visitors of 100,000+ websites including Trezor.