Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
A supply chain attack on Brevo's infrastructure on September 14, 2026, compromised over 100,000 customer websites by injecting malicious code into Brevo's JavaScript assets and widgets. The attack delivered a WordPress plugin backdoor that installed automatically when site administrators visited their sites logged in, and ClickFix overlays targeting regular visitors. Attackers modified CDN-hosted files and created malicious subdomains under sendibt1.com, likely after gaining access to Brevo's Cloudflare account. The malicious activity lasted about four hours. Brevo's high-profile clients, including eBay and Louis Vuitton, increase the potential impact of this attack.
AI Analysis
Technical Summary
On September 14, 2026, attackers conducted a supply chain attack against Brevo by compromising its infrastructure and injecting malicious code into JavaScript assets and widgets served to over 100,000 customer websites. The attack involved modification of CDN-hosted files and creation of malicious subdomains under sendibt1.com, with evidence indicating attackers accessed Brevo's Cloudflare account to alter DNS records and dynamically rewrite content. Two payloads were delivered: a WordPress plugin backdoor that installed automatically when site administrators visited their sites while logged in, and ClickFix overlays targeting regular visitors. The attack window was approximately four hours. Brevo's clientele includes major organizations such as eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential reach and impact.
Potential Impact
The attack compromised the integrity of Brevo's JavaScript assets and widgets, resulting in the automatic installation of a WordPress backdoor on over 100,000 customer websites. This backdoor could allow persistent unauthorized access to affected WordPress sites. Additionally, ClickFix overlays targeted regular visitors, potentially enabling further malicious activity such as data theft or manipulation. The compromise of Brevo's Cloudflare account allowed attackers to modify DNS records and rewrite content dynamically, increasing the attack's stealth and effectiveness. The involvement of high-profile clients suggests a significant potential impact on a broad and diverse set of organizations.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Since this is a supply chain attack involving Brevo's infrastructure and CDN assets, remediation requires Brevo to secure its infrastructure, revoke unauthorized access to its Cloudflare account, and restore clean JavaScript assets and widgets. Affected site administrators should audit their WordPress installations for unauthorized plugins or backdoors and remove any malicious components. Monitoring for unusual DNS changes and network traffic related to the malicious subdomains (sendibt1.com and its variants) is recommended. Patch status is not yet confirmed — check Brevo's official advisory for current remediation guidance.
Indicators of Compromise
- domain: ecomscan.com
- url: https://cdn10.sendibt1.com/p/wm.zip
- domain: cdn10.sendibt1.com
- hash: 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca
- hash: 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7
- hash: 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308
- hash: 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5
- hash: f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782
- hash: fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09
- url: https://cdn2.sendibt1.com/f.js
- url: https://cdn9.sendibt1.com/f.js
- domain: cdn.sendibt1.com
- domain: cdn11.sendibt1.com
- domain: cdn2.sendibt1.com
- domain: cdn3.sendibt1.com
- domain: cdn4.sendibt1.com
- domain: cdn9.sendibt1.com
Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Description
A supply chain attack on Brevo's infrastructure on September 14, 2026, compromised over 100,000 customer websites by injecting malicious code into Brevo's JavaScript assets and widgets. The attack delivered a WordPress plugin backdoor that installed automatically when site administrators visited their sites logged in, and ClickFix overlays targeting regular visitors. Attackers modified CDN-hosted files and created malicious subdomains under sendibt1.com, likely after gaining access to Brevo's Cloudflare account. The malicious activity lasted about four hours. Brevo's high-profile clients, including eBay and Louis Vuitton, increase the potential impact of this attack.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On September 14, 2026, attackers conducted a supply chain attack against Brevo by compromising its infrastructure and injecting malicious code into JavaScript assets and widgets served to over 100,000 customer websites. The attack involved modification of CDN-hosted files and creation of malicious subdomains under sendibt1.com, with evidence indicating attackers accessed Brevo's Cloudflare account to alter DNS records and dynamically rewrite content. Two payloads were delivered: a WordPress plugin backdoor that installed automatically when site administrators visited their sites while logged in, and ClickFix overlays targeting regular visitors. The attack window was approximately four hours. Brevo's clientele includes major organizations such as eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential reach and impact.
Potential Impact
The attack compromised the integrity of Brevo's JavaScript assets and widgets, resulting in the automatic installation of a WordPress backdoor on over 100,000 customer websites. This backdoor could allow persistent unauthorized access to affected WordPress sites. Additionally, ClickFix overlays targeted regular visitors, potentially enabling further malicious activity such as data theft or manipulation. The compromise of Brevo's Cloudflare account allowed attackers to modify DNS records and rewrite content dynamically, increasing the attack's stealth and effectiveness. The involvement of high-profile clients suggests a significant potential impact on a broad and diverse set of organizations.
Defensive Guidance
No official patch or remediation guidance is provided in the available data. Since this is a supply chain attack involving Brevo's infrastructure and CDN assets, remediation requires Brevo to secure its infrastructure, revoke unauthorized access to its Cloudflare account, and restore clean JavaScript assets and widgets. Affected site administrators should audit their WordPress installations for unauthorized plugins or backdoors and remove any malicious components. Monitoring for unusual DNS changes and network traffic related to the malicious subdomains (sendibt1.com and its variants) is recommended. Patch status is not yet confirmed — check Brevo's official advisory for current remediation guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["http://sansec.io/research/brevo-supply-chain-attack"]
- Pulse Id
- 6aac5377abf1f1d1674825a9
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainecomscan.com | — | |
domaincdn10.sendibt1.com | — | |
domaincdn.sendibt1.com | — | |
domaincdn11.sendibt1.com | — | |
domaincdn2.sendibt1.com | — | |
domaincdn3.sendibt1.com | — | |
domaincdn4.sendibt1.com | — | |
domaincdn9.sendibt1.com | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://cdn10.sendibt1.com/p/wm.zip | — | |
urlhttps://cdn2.sendibt1.com/f.js | — | |
urlhttps://cdn9.sendibt1.com/f.js | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca | — | |
hash4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 | — | |
hash58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 | — | |
hash9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 | — | |
hashf67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 | — | |
hashfe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 | — |
Threat ID: 6aacfa7155bf5e2cf5c39c46
Added to database: 09/18/2026, 08:46:41 UTC
Last enriched: 09/18/2026, 09:01:43 UTC
Last updated: 09/18/2026, 10:24:43 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.