
A breach affecting Brevo infrastructure has pushed malicious JavaScript to more than 100,000 websites through Brevo-hosted widgets and scripts.
According to a report from the Sansec Forensics Team, attackers modified Brevo resources on September 14 to deliver malware that attempted to install a malicious WordPress plugin when logged-in administrators visited affected sites. Other visitors were shown a ClickFix-style verification page designed to trick them into copying and executing a malicious command.
Sansec observed the malicious activity between 16:05 and 20:13 UTC on September 14. Its Content Security Policy monitoring system recorded 2,549 violation reports across 12 monitored sites during and after the attack window, while modified copies of Brevo’s sdk-loader.js and brevo-conversations.js scripts were seen loading f.js from attacker-controlled subdomains under sendibt1.com.
Brevo, formerly known as Sendinblue, provides email marketing, transactional messaging, customer relationship management, forms, and website chat services. The company says its customers include organizations such as eBay, Louis Vuitton, Michelin, and Amnesty International, giving compromises of its widely embedded JavaScript substantial downstream reach.
Sansec found the malicious loader on Brevo’s own website, booking pages, hosted forms, unsubscribe pages, and its Conversations chat widget. Websites embedding Brevo’s tracking SDK or chat components could therefore serve the malware without their operators modifying anything themselves.

The malware checked whether visitors were authenticated to WordPress. If so, it attempted to upload a plugin from cdn10.sendibt1.com/p/wm.zip using the administrator’s existing session. Sansec was unable to recover the plugin and therefore could not verify its functionality, although the researchers suspect it was intended to provide persistent backdoor access.
Unauthenticated visitors instead received a full-screen ClickFix prompt instructing them to prove they were human by pasting a command from their clipboard and executing it. The malware also contained checks intended to avoid crawlers, developers, and automated scanners.
The incident follows a separate breach Brevo disclosed on September 10. Brevo said an attacker exploited improperly scoped SAML SSO access to reach 138 customer accounts, exporting contacts from 43 and sending phishing emails from six. The company said it closed that access path at 08:30 UTC and reset active sessions.
Sansec believes the September 14 compromise may have involved Brevo’s Cloudflare account because attackers were apparently able to create DNS records and dynamically alter content across multiple Brevo-controlled domains. This remains a hypothesis, and Brevo has not publicly confirmed the root cause Sansec described.
The malicious hosts stopped resolving on September 15, and Brevo’s affected files have since been restored. WordPress administrators using Brevo services should review September 14 logs for plugin uploads to /wp-admin/update.php?action=upload-plugin, check recently installed or hidden plugins, and compare filesystem contents with the WordPress admin interface. Users who followed a suspicious “verify you are human” prompt should run a full antivirus scan on the affected device.






Leave a Reply