Brevo Supply Chain Breach Propagates WordPress Backdoors and ClickFix Malware to Over 100,000 Websites

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Brevo Supply Chain Compromise Exposes Websites to Malware

A recent supply-chain breach involving Brevo has perilously transformed common web tools into conduits for malware distribution.

Malicious actors injected nefarious JavaScript into the services utilized by customer websites, thereby jeopardizing the security of both visitors and WordPress administrators.

According to investigative reports, the nefarious activities infiltrated over 100,000 customer sites on September 14.

Individuals who accessed compromised sites, interacted with chat features, filled out sign-up forms, or visited email-linked unsubscribe pages were met with a counterfeit verification prompt that aimed to coerce them into executing potentially harmful commands.

Researchers from Sansec identified this two-fold operation by tracking modified scripts across Brevo’s various services and customer integrations.

The first route targeted WordPress administrators who were logged in, while the second utilized a ClickFix overlay to ensnare unsuspecting visitors.

In a report disseminated to Cyber Security News (CSN), Sansec articulated that this incident exemplifies how a single compromised trusted web component can rapidly exacerbate an intrusion.

Rather than infiltrating individual websites independently, attackers opted to undermine a shared service, leveraging its extensive reach to disseminate harmful content to a vast audience.

Details of the Brevo Supply Chain Attack

The insidious code was delivered between 16:05:18 and 20:12:53 UTC on September 14, surfacing on Brevo-hosted pages and within JavaScript used for a website tracker and chat widget, thereby creating vulnerabilities wherever those components were integrated.

When a visitor was already authenticated in WordPress, the rogue script endeavored to install a plugin via the administrator’s active session.

Although Sansec was unable to recover this plugin, it assessed that it was likely to function as a backdoor, a concern echoed in reports regarding trusted WordPress plugin vulnerabilities that allow sustained access.

For visitors, the script generated a full-page ClickFix prompt masquerading as a human-verification measure.

This illicit interaction prompted users to copy a command to their clipboard and execute it, converting a standard web interaction into malware activation without compromising browser security.

During the time window of the attack, monitoring recorded 2,549 content-security-policy violation reports across 12 different sites.

The malicious hosts ceased operation on September 15, and affected code has since shown clean status at the origin; however, the presence of cached copies and compromised sites remains a critical issue.

Initial disclosures indicated six hijacked customer accounts, but Sansec’s findings imply a broader event impacting shared delivery infrastructures.

This differentiation is vital, as a compromise of a hosted asset can affect sites that never had their individual account credentials compromised.

ClickFix Exposure and Recommended Responses

ClickFix operates by coercing users rather than using stealthy downloads. It employs deceptive browser checks that compel individuals to undertake final actions themselves, a method observable in recent ClickFix malware campaigns that successfully transform clipboard activities into initial footholds on devices.

Site proprietors employing the affected tracker, chat widget, or hosted form should meticulously audit web-server logs for WordPress upload and activation requests.

Additionally, they ought to inspect plugins installed or activated on September 14 and conduct file comparisons with the administrator console, as malicious plugins may be cleverly disguised from typical oversight.

Users who interacted with the verification prompt and executed commands should conduct a comprehensive antivirus scan without delay and report any anomalous device behavior.

Organizations must remind personnel and clients that authentic websites do not necessitate the execution of terminal commands or active prompts to complete security verification.

Security teams ought to preserve essential logs prior to their normal retention period concluding, reset privileged accounts where pertinent, and scrutinize for unfamiliar files or modifications.

Monitoring third-party JavaScript and constraining administrator sessions can mitigate the risk of a singular supplier compromise escalating into a broader site breach.

Available evidence indicates that attackers may have gained entry to Brevo’s Cloudflare environment, allowing for DNS alterations and modified responses across interconnected domains.

A person in a gray hoodie working on a laptop showing lines of code, seated at a white desk.

While this remains an assessment rather than a confirmed cause, it underscores the necessity for scrutinizing third-party scripts, maintaining restricted administrative access, and implementing rapid integrity checks in the aftermath of supplier incidents.

Indicators of Compromise (IoCs):

TypeIndicatorDescription
Modified JavaScript URLhttps://cdn.brevo.com/js/sdk-loader.jsAffected tracker loader file
Modified JavaScript URLhttps://cdn.brevo.com/js/brevo-conversations.jsChat-widget JavaScript asset mentioned in the investigation
Malicious script URLhttps://cdn9.sendibt1.com/f.jsInjected malware script present on affected Brevo pages
Domaincdn.sendibt1.comMalicious loader infrastructure, reported as NXDOMAIN from September 15
IP Address104.21.77.104Address associated with cdn.sendibt1.com

Source link: Cybersecuritynews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading