Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
Brief
A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators.
The activity reached more than 100,000 customer sites on September 14, according to the investigation. People who opened affected sites, chat features, sign-up forms, or email-linked unsubscribe pages could receive a fake verification prompt designed to make them run a command.
Researchers at Sansec identified the two-part operation after tracing altered scripts across Brevo-owned services and customer integrations. The first path targeted logged-in WordPress administrators, while the second used a ClickFix overlay against ordinary visitors.
