Brevo Supply Chain Compromise Exposes Websites to Malware
A recent supply-chain breach involving Brevo has perilously transformed common web tools into conduits for malware distribution.
Malicious actors injected nefarious JavaScript into the services utilized by customer websites, thereby jeopardizing the security of both visitors and WordPress administrators.
According to investigative reports, the nefarious activities infiltrated over 100,000 customer sites on September 14.
Individuals who accessed compromised sites, interacted with chat features, filled out sign-up forms, or visited email-linked unsubscribe pages were met with a counterfeit verification prompt that aimed to coerce them into executing potentially harmful commands.
Researchers from Sansec identified this two-fold operation by tracking modified scripts across Brevo’s various services and customer integrations.
The first route targeted WordPress administrators who were logged in, while the second utilized a ClickFix overlay to ensnare unsuspecting visitors.
In a report disseminated to Cyber Security News (CSN), Sansec articulated that this incident exemplifies how a single compromised trusted web component can rapidly exacerbate an intrusion.
Rather than infiltrating individual websites independently, attackers opted to undermine a shared service, leveraging its extensive reach to disseminate harmful content to a vast audience.
Details of the Brevo Supply Chain Attack
The insidious code was delivered between 16:05:18 and 20:12:53 UTC on September 14, surfacing on Brevo-hosted pages and within JavaScript used for a website tracker and chat widget, thereby creating vulnerabilities wherever those components were integrated.
When a visitor was already authenticated in WordPress, the rogue script endeavored to install a plugin via the administrator’s active session.
Although Sansec was unable to recover this plugin, it assessed that it was likely to function as a backdoor, a concern echoed in reports regarding trusted WordPress plugin vulnerabilities that allow sustained access.
For visitors, the script generated a full-page ClickFix prompt masquerading as a human-verification measure.
This illicit interaction prompted users to copy a command to their clipboard and execute it, converting a standard web interaction into malware activation without compromising browser security.
During the time window of the attack, monitoring recorded 2,549 content-security-policy violation reports across 12 different sites.
The malicious hosts ceased operation on September 15, and affected code has since shown clean status at the origin; however, the presence of cached copies and compromised sites remains a critical issue.
Initial disclosures indicated six hijacked customer accounts, but Sansec’s findings imply a broader event impacting shared delivery infrastructures.
This differentiation is vital, as a compromise of a hosted asset can affect sites that never had their individual account credentials compromised.
ClickFix Exposure and Recommended Responses
ClickFix operates by coercing users rather than using stealthy downloads. It employs deceptive browser checks that compel individuals to undertake final actions themselves, a method observable in recent ClickFix malware campaigns that successfully transform clipboard activities into initial footholds on devices.
Site proprietors employing the affected tracker, chat widget, or hosted form should meticulously audit web-server logs for WordPress upload and activation requests.
Additionally, they ought to inspect plugins installed or activated on September 14 and conduct file comparisons with the administrator console, as malicious plugins may be cleverly disguised from typical oversight.
Users who interacted with the verification prompt and executed commands should conduct a comprehensive antivirus scan without delay and report any anomalous device behavior.
Organizations must remind personnel and clients that authentic websites do not necessitate the execution of terminal commands or active prompts to complete security verification.
Security teams ought to preserve essential logs prior to their normal retention period concluding, reset privileged accounts where pertinent, and scrutinize for unfamiliar files or modifications.
Monitoring third-party JavaScript and constraining administrator sessions can mitigate the risk of a singular supplier compromise escalating into a broader site breach.
Available evidence indicates that attackers may have gained entry to Brevo’s Cloudflare environment, allowing for DNS alterations and modified responses across interconnected domains.

While this remains an assessment rather than a confirmed cause, it underscores the necessity for scrutinizing third-party scripts, maintaining restricted administrative access, and implementing rapid integrity checks in the aftermath of supplier incidents.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| Modified JavaScript URL | https://cdn.brevo.com/js/sdk-loader.js | Affected tracker loader file |
| Modified JavaScript URL | https://cdn.brevo.com/js/brevo-conversations.js | Chat-widget JavaScript asset mentioned in the investigation |
| Malicious script URL | https://cdn9.sendibt1.com/f.js | Injected malware script present on affected Brevo pages |
| Domain | cdn.sendibt1.com | Malicious loader infrastructure, reported as NXDOMAIN from September 15 |
| IP Address | 104.21.77.104 | Address associated with cdn.sendibt1.com |
Source link: Cybersecuritynews.com.





