Skip to content
100,000+ WordPress sites infected via Brevo supply chain attack

100,000+ WordPress sites infected via Brevo supply chain attack

Cyberinsider Alex Lekander September 17, 2026

A breach affecting Brevo infrastructure has pushed malicious JavaScript to more than 100,000 websites through Brevo-hosted widgets and scripts.

According to a report from the Sansec Forensics Team , attackers modified Brevo resources on September 14 to deliver malware that attempted to install a malicious WordPress plugin when logged-in administrators visited affected sites. Other visitors were shown a ClickFix-style verification page designed to trick them into copying and executing a malicious command.

Sansec observed the malicious activity between 16:05 and 20:13 UTC on September 14. Its Content Security Policy monitoring system recorded 2,549 violation reports across 12 monitored sites during and after the attack window, while modified copies of Brevo’s sdk-loader.js and brevo-conversations.js scripts were seen loading f.js from attacker-controlled subdomains under sendibt1.com.

Brevo, formerly known as Sendinblue, provides email marketing, transactional messaging, customer relationship management, forms, and website chat services. The company says its customers include organizations such as eBay, Louis Vuitton, Michelin, and Amnesty International, giving compromises of its widely embedded JavaScript substantial downstream reach.

The malware checked whether visitors were authenticated to WordPress. If so, it attempted to upload a plugin from cdn10.sendibt1.com/p/wm.zip using the administrator’s existing session. Sansec was unable to recover the plugin and therefore could not verify its functionality, although the researchers suspect it was intended to provide persistent backdoor access.

Unauthenticated visitors instead received a full-screen ClickFix prompt instructing them to prove they were human by pasting a command from their clipboard and executing it. The malware also contained checks intended to avoid crawlers, developers, and automated scanners.

The incident follows a separate breach Brevo disclosed on September 10 . Brevo said an attacker exploited improperly scoped SAML SSO access to reach 138 customer accounts, exporting contacts from 43 and sending phishing emails from six. The company said it closed that access path at 08:30 UTC and reset active sessions.

Sansec believes the September 14 compromise may have involved Brevo’s Cloudflare account because attackers were apparently able to create DNS records and dynamically alter content across multiple Brevo-controlled domains. This remains a hypothesis, and Brevo has not publicly confirmed the root cause Sansec described.

The malicious hosts stopped resolving on September 15, and Brevo’s affected files have since been restored. WordPress administrators using Brevo services should review September 14 logs for plugin uploads to /wp-admin/update.php?action=upload-plugin, check recently installed or hidden plugins, and compare filesystem contents with the WordPress admin interface. Users who followed a suspicious “verify you are human” prompt should run a full antivirus scan on the affected device.

New SparroWocky backdoor deployed in attacks on governments

Revolut hackers used infostealer to hijack Italian government emails

Apple uses secure camera hardware to verify photos are real captures

Google patches Pixel modem zero-day exploited in targeted attacks

Iranian malware steals Telegram and WhatsApp data from targets

Steam client flaw with no fix enables privilege elevation on Windows

Alex Lekander is the Editor-in-Chief and owner of CyberInsider.com. With a passion for cybersecurity and privacy topics, Alex launched this website in 2020. His background and expertise cover privacy research, technical writing, software testing, and site administration. He holds a Bachelor of Science and a Master of Science from Johns Hopkins University.