Skip to main content

Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware

0
Medium
Published: 09/17/2026 (09/17/2026, 20:54:15 UTC)
Source: AlienVault OTX General

Description

A supply chain attack on Brevo's infrastructure on September 14, 2026, compromised over 100,000 customer websites by injecting malicious code into Brevo's JavaScript assets and widgets. The attack delivered a WordPress plugin backdoor that installed automatically when site administrators visited their sites logged in, and ClickFix overlays targeting regular visitors. Attackers modified CDN-hosted files and created malicious subdomains under sendibt1.com, likely after gaining access to Brevo's Cloudflare account. The malicious activity lasted about four hours. Brevo's high-profile clients, including eBay and Louis Vuitton, increase the potential impact of this attack.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 09:01:43 UTC

Technical Analysis

On September 14, 2026, attackers conducted a supply chain attack against Brevo by compromising its infrastructure and injecting malicious code into JavaScript assets and widgets served to over 100,000 customer websites. The attack involved modification of CDN-hosted files and creation of malicious subdomains under sendibt1.com, with evidence indicating attackers accessed Brevo's Cloudflare account to alter DNS records and dynamically rewrite content. Two payloads were delivered: a WordPress plugin backdoor that installed automatically when site administrators visited their sites while logged in, and ClickFix overlays targeting regular visitors. The attack window was approximately four hours. Brevo's clientele includes major organizations such as eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential reach and impact.

Potential Impact

The attack compromised the integrity of Brevo's JavaScript assets and widgets, resulting in the automatic installation of a WordPress backdoor on over 100,000 customer websites. This backdoor could allow persistent unauthorized access to affected WordPress sites. Additionally, ClickFix overlays targeted regular visitors, potentially enabling further malicious activity such as data theft or manipulation. The compromise of Brevo's Cloudflare account allowed attackers to modify DNS records and rewrite content dynamically, increasing the attack's stealth and effectiveness. The involvement of high-profile clients suggests a significant potential impact on a broad and diverse set of organizations.

Defensive Guidance

No official patch or remediation guidance is provided in the available data. Since this is a supply chain attack involving Brevo's infrastructure and CDN assets, remediation requires Brevo to secure its infrastructure, revoke unauthorized access to its Cloudflare account, and restore clean JavaScript assets and widgets. Affected site administrators should audit their WordPress installations for unauthorized plugins or backdoors and remove any malicious components. Monitoring for unusual DNS changes and network traffic related to the malicious subdomains (sendibt1.com and its variants) is recommended. Patch status is not yet confirmed — check Brevo's official advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["http://sansec.io/research/brevo-supply-chain-attack"]
Pulse Id
6aac5377abf1f1d1674825a9

Indicators of Compromise

Domain

ValueDescriptionCopy
domainecomscan.com
domaincdn10.sendibt1.com
domaincdn.sendibt1.com
domaincdn11.sendibt1.com
domaincdn2.sendibt1.com
domaincdn3.sendibt1.com
domaincdn4.sendibt1.com
domaincdn9.sendibt1.com

Url

ValueDescriptionCopy
urlhttps://cdn10.sendibt1.com/p/wm.zip
urlhttps://cdn2.sendibt1.com/f.js
urlhttps://cdn9.sendibt1.com/f.js

Hash

ValueDescriptionCopy
hash26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca
hash4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7
hash58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308
hash9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5
hashf67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782
hashfe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09

Threat ID: 6aacfa7155bf5e2cf5c39c46

Added to database: 09/18/2026, 08:46:41 UTC

Last enriched: 09/18/2026, 09:01:43 UTC

Last updated: 09/18/2026, 10:24:43 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses