Back Cyberinsider 100,000+ WordPress sites infected via Brevo supply chain attack
A breach affecting Brevo infrastructure has pushed malicious JavaScript to more than 100,000 websites through Brevo-hosted widgets and scripts.
According to a report from the Sansec Forensics Team , attackers modified Brevo resources on September 14 to deliver malware that attempted to install a malicious WordPress plugin when logged-in administrators visited affected sites. Other visitors were shown a ClickFix-style verification page designed to trick them into copying and executing a malicious command.
Sansec observed the malicious activity between 16:05 and 20:13 UTC on September 14. Its Content Security Policy monitoring system recorded 2,549 violation reports across 12 monitored sites during and after the attack window, while modified copies of Brevo’s sdk-loader.js and brevo-conversations.js scripts were seen loading f.js from attacker-controlled subdomains under sendibt1.com.
Brevo, formerly known as Sendinblue, provides email marketing, transactional messaging, customer relationship management, forms, and website chat services. The company says its customers include organizations such as eBay, Louis Vuitton, Michelin, and Amnesty International, giving compromises of its widely embedded JavaScript substantial downstream reach.
The malware checked whether visitors were authenticated to WordPress. If so, it attempted to upload a plugin from cdn10.sendibt1.com/p/wm.zip using the administrator’s existing session. Sansec was unable to recover the plugin and therefore could not verify its functionality, although the researchers suspect it was intended to provide persistent backdoor access.
Unauthenticated visitors instead received a full-screen ClickFix prompt instructing them to prove they were human by pasting a command from their clipboard and executing it. The malware also contained checks intended to avoid crawlers, developers, and automated scanners.
The incident follows a separate breach Brevo disclosed on September 10 . Brevo said an attacker exploited improperly scoped SAML SSO access to reach 138 customer accounts, exporting contacts from 43 and sending phishing emails from six. The company said it closed that access path at 08:30 UTC and reset active sessions.
Sansec believes the September 14 compromise may have involved Brevo’s Cloudflare account because attackers were apparently able to create DNS records and dynamically alter content across multiple Brevo-controlled domains. This remains a hypothesis, and Brevo has not publicly confirmed the root cause Sansec described.
The malicious hosts stopped resolving on September 15, and Brevo’s affected files have since been restored. WordPress administrators using Brevo services should review September 14 logs for plugin uploads to /wp-admin/update.php?action=upload-plugin, check recently installed or hidden plugins, and compare filesystem contents with the WordPress admin interface. Users who followed a suspicious “verify you are human” prompt should run a full antivirus scan on the affected device.
New SparroWocky backdoor deployed in attacks on governments
Revolut hackers used infostealer to hijack Italian government emails
Apple uses secure camera hardware to verify photos are real captures
Google patches Pixel modem zero-day exploited in targeted attacks
Iranian malware steals Telegram and WhatsApp data from targets
Steam client flaw with no fix enables privilege elevation on Windows
Alex Lekander is the Editor-in-Chief and owner of CyberInsider.com. With a passion for cybersecurity and privacy topics, Alex launched this website in 2020. His background and expertise cover privacy research, technical writing, software testing, and site administration. He holds a Bachelor of Science and a Master of Science from Johns Hopkins University.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
