Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Brevo Cyber Attack. Show all posts

Brevo Breach Exposes Customer Websites to ClickFix Malware


Email marketing and customer relationship management platform Brevo, formerly known as Sendinblue, suffered a supply chain attack in which malicious code was able to reach Brevo's own websites as well as customers' websites utilizing embedded Brevo services. 

Researchers at Sansec discovered that the incident was much more extensive than the six accounts previously revealed. When Brevo infrastructure was compromised on September 14, 2026, malicious JavaScript began to be served. In addition, Sansec found evidence that more than 100,000 customer websites utilizing Brevo components may have been exposed as a result of the attack. 

There were two main infection paths used in the campaign: a malicious WordPress plugin that targeted site administrators and a ClickFix overlay that was displayed to visitors. 

Malicious Code Reached Embedded Brevo Components

Brevo-hosted pages as well as JavaScript resources commonly embedded in customer websites were identified as containing the injected code. These included Brevo trackers, Conversations chat widgets, as well as other forms hosted on Brevo servers. 

Modified versions of the JavaScript assets directed browsers to infrastructure controlled by attackers, which served the malicious malware loader. Sansec identified several malicious subdomains under the Brevo domain sendibt1.com. A number of hostnames were affected, including cdn.sendibt1.com, cdn2.sendibt1.com, cdn3.sendibt1.com, cdn4.sendibt1.com, cdn9.sendibt1.com, cdn10.sendibt1.com, and cdn11.sendibt1.com. 

A SSL certificate for cdn.sendibt1.com was also discovered on August 25, which indicates that the attackers had gained access to Brevo's DNS records. A malicious content display was observed on September 14 from approximately 16:05 until 20:13 UTC, which was observed by researchers. 

A total of 2,549 breaches of Content Security Policy were reported across 12 sites during and after the attack window. These hosts stopped resolving on September 15, while the affected files were reported clean at the site of origin. 

ClickFix Campaign Targeted Website Visitors

Injected malware delivered different payloads depending on the visitor. When a visitor was detected as a WordPress administrator, it attempted to install a plugin from a Brevo subdomain controlled by the attacker. A fake verification prompt was displayed using the ClickFix technique to visitors, instructing them to copy a command and execute it under the pretext of demonstrating their humanity. According to Sansec, the malware did not activate for crawlers, developers, or automated scanners, therefore preventing it from being detected during routine inspections. 

WordPress Sites Faced a Deeper Threat 

A more significant risk was posed to WordPress administrators by the attack. When the compromised Brevo script identified an administrator already logged into a WordPress site, it attempted to download and install plugins from attacker-controlled infrastructure. 

BleepingComputer examined a copy of the plugin, which was disguised as Web Media Optimizer, but was actually a JavaScript loader and persistent backdoor. Installing this plugin allowed it to hide from the normal WordPress plugin list and copy itself into the must-use plugins directory, making its removal more difficult. Additionally, the plugin contacted attacker-controlled infrastructure to obtain additional JavaScript, allowing malicious content to continue loading even if the remote server was unavailable, as researchers discovered. 

A critical feature of the plugin was that it contained a hardcoded authentication mechanism capable of creating a valid administrator session without requiring the legitimate administrator password. This allowed attackers to continue access to a compromised WordPress installation beyond Brevo's original exposure period. 

Brevo Took Down the Malicious Infrastructure

After detecting the intrusion, Brevo removed the malicious Cloudflare Worker and associated routes. As a result of the compromise, Brevo revoked its API key and credentials, removed attacker-controlled hostnames and purified edge caches. Additionally, the hardcoded Cloudflare credential was removed from the source code of the company. 

Sansec reports that malicious hosts began to cease resolving on September 15 and Brevo's affected files were restored to their original versions. Although the delivery window ended, the malware was not removed from WordPress sites where the rogue plugin had already been installed. Additionally, Brevo SSO security incident reported on September 10 also occurred following the incident. It was reported that six customer accounts were accessed unauthorised and were used for phishing, as well as contact data exported from 43 other accounts in that incident. 

A public connection has not been established between Brevo's earlier incident and Cloudflare's subsequent compromise. The Brevo incident illustrates the threat of third-party services that extend beyond the infrastructure of the provider and affect websites which utilize embedded scripts. Additionally, the combination of ClickFix lures and persistent WordPress backdoors creates a higher risk for website administrators and visitors alike.