· via dev.to (home feed)
Brevo script compromise exposed 100,000+ sites to WordPress backdoors and ClickFix
Altered Brevo tracking and chat scripts served attacker code for roughly four hours on 14 September, hitting WordPress admins with a backdoor attempt and other visitors with fake verification prompts.

On 14 September 2026, during a window running from 16:05 to 20:13 UTC, script files that websites load directly from the marketing platform Brevo were altered to serve attacker-controlled code. According to an analysis by the Dutch security firm Sansec, the exposure reached more than 100,000 sites. Brevo stopped serving the modified files, but as a write-up on dev.to points out, any site that was infected during those hours stays infected until someone cleans it.
How the scripts were altered
Sansec found that a single added line in files hosted by Brevo pulled in the attackers' script. The affected files were the tracking code loader sdk-loader.js, the chat widget brevo-conversations.js, and the Brevo-hosted pages used for sign-up forms and the unsubscribe links inside newsletters.
The root cause is still unconfirmed. Sansec's working hypothesis is that the attackers gained access to Brevo's Cloudflare account, which would explain both the new DNS records that appeared and the rewritten responses. At the time the dev.to article was written, Brevo had not published a statement about the 14 September event.
Two payloads, two audiences
The malicious script behaved differently depending on who loaded it. On WordPress sites, if an administrator logged in to wp-admin opened a public page of their own site during the window, the script used their session to upload and activate a plugin fetched from the attackers. Sansec did not recover that plugin, but assesses it as most likely a backdoor offering hidden, persistent access.
Every other visitor saw a full-page fake human-verification prompt. It placed a command on the clipboard and told the visitor to paste and run it, a social-engineering technique known as ClickFix. No browser flaw is involved; it works only because the person executes the command themselves.
Sansec also notes that the script stayed quiet for crawlers, developer tools and automated scanners, which means a quick manual look at a site afterwards proves nothing.
What to check on a WordPress site
For sites that embedded the Brevo tracker, the chat widget or a hosted Brevo form, Sansec's recommendations, relayed in the dev.to write-up, are:
- Search web server access logs from 14 September for a POST to /wp-admin/update.php?action=upload-plugin followed shortly by a GET to /wp-admin/plugins.php?action=activate.
- Review any plugin that was installed or activated on that date.
- Compare the plugin directory on disk against the list in the admin screen, because a malicious plugin can hide itself from that list.
Logs should be preserved before rotation removes them, since many hosts keep them for only days or weeks. Sansec also cautions against blocking the apex domain sendibt1.com: that domain carries Brevo's legitimate open and click tracking, and only subdomains such as cdn2.sendibt1.com served malicious content.
A separate Brevo breach earlier in September
This was not the only incident at the company that month. On 10 September, Brevo publicly disclosed that an attacker had abused a flaw in how it handled SAML single sign-on and reached 138 customer accounts. Six of those accounts were used to send phishing emails to the contacts stored in them, and 43 had their contact lists exported. Brevo says it closed the route the same morning and signed out every user on the platform. The write-up does not establish a connection between the two events.
If someone followed the fake prompt
One rule from the article applies to every site, not just this one: no legitimate website asks you to open a Run dialog, a terminal or a command prompt to pass a security check. Anyone who saw such a prompt during the window and complied ran a malicious command on their own machine, and Sansec's advice is a prompt, full antivirus scan.
Why it matters
Embedded third-party scripts are trusted implicitly by every page that loads them, so a single compromise at the vendor becomes a compromise at every customer site simultaneously, and here that meant an estimated six-figure number of domains. The attack deliberately targeted WordPress administrators, aiming not at a quick data theft but at persistent access to sites. Because the payload hid itself from scanners and casual inspection, access logs are the only reliable signal, and that evidence is perishable. Even organisations that outsource their website entirely are exposed, and the practical next step is written, dated answers from whoever runs the site: whether Brevo code was embedded, whether the 14 September logs were checked, and what they showed.
- #supply-chain
- #security
- #brevo
- #wordpress
- #clickfix