Cybersecurity

Brevo Supply Chain Breach Injects ClickFix Malware into Customer Websites

Brevo confirmed that attackers stole an API key for its Cloudflare account and used it to modify the content of its websites and JavaScript files embedded in customer websites, resulting in the distribution of ClickFix pages and malware. The campaign included adding a persistent backdoor to some WordPress sites, while the company said its application interface, customer data, and email delivery infrastructure were not affected.

2026-09-17
4 min read
4 views
فريق تحرير certi.news
Brevo Supply Chain Breach Injects ClickFix Malware into Customer Websites

Brevo confirmed that attackers exploited a stolen Cloudflare API key to create a malicious Worker that modified content at the edge of the distribution network and injected ClickFix scripts into the company’s websites and JavaScript files that customers embed in their own sites. The exposure lasted approximately five and a half hours on September 14, 2026, between 16:07 and 20:30 UTC, according to Brevo’s subsequent investigation.

The modification affected pages on the brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, and sibforms.com domains, in addition to Brevo form scripts, the Brevo Conversations interface, and the Brevo SDK loader that customers add to their websites. As a result, the risk was not limited to visitors of the company’s domains but extended to websites using its software components.

How Were the Security Measures Bypassed?

Brevo explained that the stolen key was long-lived, had full permissions on the account, and was embedded in the application’s source code. This enabled the attackers to create Cloudflare Workers, routes, and DNS records across Brevo’s domains without triggering an alert. The malicious Worker also rewrote responses at the edge and removed security headers, including Content-Security-Policy, while the origin servers and original files remained unmodified; therefore, file-integrity checks did not detect the change.

The company believes that the key may have been compromised since late August, but said it found no evidence of malicious activity before the attack window. After discovering the incident, it removed the Worker and its routes, revoked the key and the credentials created by the attackers, deleted the credentials embedded in the code, removed the hostnames controlled by the attackers, and then purged edge content caches.

From ClickFix to a WordPress Backdoor

According to Sansec, the impact may have reached as many as 100,000 websites using the affected Brevo components. Visitors saw a fake Cloudflare verification page followed by ClickFix instructions urging them to run a command on Windows. On WordPress sites that embedded the affected Brevo interface, the script checked whether the visitor was logged in as an administrator and attempted to load a malicious plugin from an archive named Web Media Optimizer.

BleepingComputer found that the plugin operates as a persistent backdoor and JavaScript loader, hides itself from the WordPress plugins list, copies itself into the must-use plugins directory, and periodically connects to a server controlled by the attackers. It also contained a hard-coded authentication key that could be used to create a valid login session for a WordPress administrator account without knowing the password.

What Should Operators Review?

Brevo said that app.brevo.com, its API, email delivery infrastructure, and customer account data were not affected. Nevertheless, WordPress administrators who visited an affected site while logged in as administrators on September 14 should inspect plugins that were installed or activated that day, remove any unfamiliar plugin, and change administrative account passwords when indicators of compromise are found.

Editorial reading: The incident shows that the integrity of original files is not enough when an attacker can modify responses at the CDN layer. The practical risk here arose from broad Cloudflare permissions and the distribution of third-party scripts across customer websites, while the connection between this breach and a separate SSO incident disclosed by Brevo on September 10 remains unresolved; the company did not answer BleepingComputer’s questions about whether the two incidents were linked.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news