Description

A suspected supply chain compromise involving Brevo hosted JavaScript assets exposed visitors and WordPress administrators across more than 100000 websites to malicious activity. Attackers reportedly injected harmful scripts into Brevo services including tracking tools forms and conversation widgets. The campaign was observed on September 14 and involved malware that could deliver a WordPress backdoor to authenticated administrators and display ClickFix style fake verification pages to regular visitors. The attack was possible because many websites trusted and embedded Brevo resources directly into their pages. When the compromised scripts were loaded the malicious code could identify WordPress administrators and attempt to install a plugin through their existing authenticated browser session. Other visitors could receive a fake human verification prompt designed to persuade them to execute a malicious command manually. Researchers also reported that the malicious infrastructure operated through several sendibt1.com subdomains associated with Brevo. This incident highlights the security risks created by third party JavaScript integrations. A compromise of a trusted service can allow attackers to reach a large number of organizations without directly exploiting vulnerabilities in each individual website. Organizations using Brevo services should review web and WordPress logs for September 14 and investigate unexpected plugin installations or activation activity. Security teams should also check DNS proxy endpoint and CSP logs for connections to suspicious sendibt1.com subdomains. Any user who executed commands shown by a fake verification page should receive endpoint investigation and appropriate incident response.