Brevo Supply Chain Attack: How One API Key Hit 100,000+ Sites
Brevo’s scripts run on more than 100,000 websites. On September 14, 2026, one Cloudflare API key, stored in Brevo’s source code, let an attacker turn those scripts into a malware delivery channel for about four hours. The Brevo supply chain attack showed visitors fake verification pages and tried to plant a hidden backdoor through logged-in WordPress admins. On sites no one has checked, that backdoor can still be live.
TL;DR
- What happened: On September 14, 2026, a malicious Cloudflare Worker rewrote Brevo’s tracker, chat widget, and forms script at the CDN edge for about four hours.
- Who was exposed: Visitors to 100,000+ sites that embed those scripts saw fake “verify you are human” ClickFix pages. Logged-in WordPress admins were targeted with a hidden backdoor plugin.
- Why tools missed it: Brevo’s origin files never changed, and their Last-Modified dates stayed the same. Only the browser saw the attack.
- What to do now: If you run WordPress with Brevo, check wp-content/mu-plugins for “Web Media Optimizer.” The injection stopped on September 14. The backdoors did not.
What is a client-side supply chain attack?
A client-side supply chain attack compromises code that a website loads from a third party, such as a chat widget, tracker, or form script. The malicious code runs in visitors’ browsers, but the site owner never changes a line of code. The entry point is the vendor, or the infrastructure between the vendor and the browser.
What happened in the Brevo supply chain attack?
Brevo, formerly Sendinblue, is an email marketing and customer engagement platform. You add its features to your site by embedding its scripts: sign-up forms, a chat widget, and a tracker. Public indexes list more than 114,000 pages that reference Brevo, Sibforms, or Sibautomation resources, and Sansec estimates the blast radius at more than 100,000 sites.
The attacker held a long-lived Cloudflare API key with full account permissions. Brevo says the key was stored in application source code and first misused in late August 2026. On September 14, the attacker used it to deploy a malicious Cloudflare Worker: a small program on Cloudflare’s edge servers that can rewrite a response before it reaches the browser.
The Worker injected JavaScript into brevo.com, sendinblue.com, and sibforms.com, and into three scripts that customers embed on their own sites:
- The tracker (SDK loader)
- The Conversations chat widget
- The sign-up forms script
Brevo-hosted forms and unsubscribe pages served the payload too. Brevo says its app, API, email delivery, and customer account data were not affected.
How the Brevo attack worked
One API key, five steps, 100,000+ sites
A key leaks
A long-lived Cloudflare API key with full account permissions sits in Brevo’s application source code. Brevo says misuse began in late August 2026.
A Worker takes over the edge
On September 14, the attacker deploys a Cloudflare Worker on Brevo’s account. It rewrites responses at the edge and strips security headers such as CSP.
Trusted scripts turn
Brevo’s tracker, chat widget, and forms script start loading code from new sendibt1.com subdomains. The origin files never change.
Visitors get hit
Visitors see a fake “verify you are human” page that tells them to run a command. Logged-in WordPress admins face a silent plugin install.
The backdoor stays
The “Web Media Optimizer” plugin hides in mu-plugins and keeps pulling ClickFix scripts from attacker servers after the window closes.
Brevo attack timeline (UTC)
| Date and time (UTC) | Event |
|---|---|
| Late August 2026 | Cloudflare API key first misused, per Brevo. No injection into customer pages before September 14. |
| September 10, 06:30 to 08:30 | Separate incident: Brevo finds and closes a SAML single sign-on flaw that exposed 138 accounts. |
| September 14, 15:01 | brevo.com starts serving the injected script. |
| September 14, 16:05 to 16:07 | Scripts embedded on customer sites start serving the payload (16:05 per Sansec, 16:07 per Brevo). |
| September 14, 19:33 | Brevo opens its incident, about 3.5 hours after customer scripts were hit. |
| September 14, 20:13 to 20:30 | Injection stops (20:13 per Sansec, 20:30 per Brevo). Brevo removes the Worker and revokes the key. |
| September 15 | The attacker’s subdomains stop resolving. |
| September 16 | Sansec publishes its technical analysis. |
What did the injected script do?
The script skipped bots, automated scanners, developers, and crawlers, which made it harder to spot. Everyone else fell into one of two groups:
- Ordinary visitors saw a full-page fake Cloudflare check that said “verify you are human.” It copied a command to the clipboard and told the visitor to paste and run it. This technique is called ClickFix: the visitor installs the malware on their own computer.
- Logged-in WordPress admins were targeted with a silent plugin install. The script tried to use their active session to upload and activate the plugin. No password was needed.
Why did origin-side security miss it?
The attack lived between Brevo’s servers and your visitors’ browsers. Every check aimed at the origin came back clean.
- File integrity: Brevo’s origin servers and files never changed. The Worker rewrote responses at the edge, so integrity checks against the origin found nothing.
- Timestamps: Sansec found the files kept the same Last-Modified dates before, during, and after the attack.
- Subresource Integrity (SRI): SRI would have blocked the altered files, because the browser checks the bytes it receives against a pinned hash. But vendor loaders change without notice, so sites rarely pin them.
- Server-side tools: WAFs, malware scanners, and code reviews watch your origin. None of them see what a vendor script does after it loads in the browser.
Brevo opened its incident at 19:33 UTC, about 3.5 hours after customer scripts started serving the payload. Without browser-side monitoring of your own pages, you wait for the vendor.
The pattern is not new. The Polyfill.io attack showed in 2024 that one shared script source can reach more than 100,000 sites, and the Elfsight incident showed how much control a widget vendor keeps over code on your pages.
Is your WordPress site still backdoored?
Brevo removed the Worker on September 14. That stopped the injection. It did not remove plugins the script had already installed.
The plugin is disguised as “Web Media Optimizer.” According to BleepingComputer’s report, it:
- Hides itself from the WordPress plugin list
- Copies itself into the must-use plugins folder (wp-content/mu-plugins) to persist
- Contacts glegchner[.]com for new ClickFix scripts to inject into your pages
- Carries a hardcoded key that lets the attacker create an admin session without a password
A password reset alone will not evict it.
What to do now if your site embeds Brevo
- Check web server logs for September 14 requests to
/wp-admin/update.php?action=upload-pluginand/wp-admin/plugins.php?action=activate. - Compare
wp-content/pluginsandwp-content/mu-pluginson disk with the plugin list in your dashboard. The backdoor hides from the list. - Search files and logs for “Web Media Optimizer,”
cdn*.sendibt1[.]com, andglegchner[.]com. - Remove the plugin first, then rotate admin passwords and sessions. Its hardcoded key can create admin sessions without a password.
- Ask staff if anyone ran a “verify you are human” command on September 14. Treat those computers as compromised.
How Reflectiz is built to catch attacks like this
In-page agents run next to the scripts they watch. Reflectiz monitors from the outside, with no agent and no code on your site. It loads your pages in a real browser, follows real user journeys, and records what every first-, third-, and fourth-party script does.
- Behavior, not file hashes. Reflectiz compares each script’s behavior to a baseline: what it loads, where it sends data, which cookies it drops, and when any of that changes. A tracker that suddenly loads code from a new domain is a behavior change, whatever its Last-Modified header says.
- Fourth-party visibility. Brevo’s scripts started pulling code from sendibt1.com subdomains they had never used. Reflectiz maps the full chain of scripts your site loads, so a new source behind a trusted vendor shows up as a new dependency.
- Alerts within hours, and after the window closes. Reflectiz scans on the schedule you set and sends alerts to Splunk, Jira, or any SIEM/SOAR through its REST API. A backdoored WordPress site can keep injecting ClickFix scripts long after Brevo’s window closed, and each new script domain on your pages is a change Reflectiz flags.
- No trust in the vendor’s infrastructure. Brevo’s origin was clean the whole time. Vendor risk ratings and origin scans had nothing to find. Reflectiz checks the code that actually reaches your visitors.
- Containment without a code deploy. With the Idle Blocking Script in place, your team can block a malicious domain from the Reflectiz console through a Content Security Policy, with no developer and a one-click revert. The Worker stripped CSP from Brevo’s responses, not from your pages, so your policy still applies. Sansec logged 2,549 CSP violation reports from 12 sites during and after the attack.
Running a Brevo widget on a payment page? Unauthorized changes to scripts as the browser receives them are what PCI DSS 11.6.1 requires you to detect.
Scope note. The September 10 SSO takeover happened inside Brevo’s platform, and client-side monitoring does not cover it. On September 14, the plugin install ran inside logged-in admin sessions. What reached visitors is what browser-side monitoring is built to flag: the ClickFix page, the new script sources, and the scripts the backdoor injects afterward.
The takeaway
The injection lasted about four hours. The backdoors did not close with it.
Every vendor script on your site runs code you don’t control, from infrastructure you can’t see. Ask what your current tools would show you if one of those scripts changed today. If the answer is nothing until the headlines, that is your visibility gap. See how Castore monitors web supply chain threats across 30+ online stores.
See what your third-party scripts actually do in your visitors’ browsers
Reflectiz maps every script on your site and flags behavior changes, with no agent and no code to install.
Sources: Brevo SSO incident write-up, Sansec research, BleepingComputer on the Brevo attack, and BleepingComputer on the Trezor phishing.
FAQs
What was the Brevo supply chain attack?
On September 14, 2026, an attacker used a Cloudflare API key stored in Brevo’s source code to deploy a malicious Cloudflare Worker. For about four hours, it injected JavaScript into Brevo’s tracker, chat widget, and forms script, which run on more than 100,000 websites. Visitors saw fake ClickFix verification pages, and logged-in WordPress admins were targeted with a backdoor plugin.
Which Brevo scripts were affected?
Brevo says three scripts that customers embed were modified: the SDK loader (tracker), the Conversations chat widget, and the sign-up forms script. brevo.com, sendinblue.com, sibforms.com, and Brevo-hosted forms and unsubscribe pages also served the payload. Brevo says its app, API, email delivery, and customer account data were not affected.
How long did the Brevo attack last?
Brevo’s own site served the injected script for about 5.5 hours, from 15:01 to 20:30 UTC on September 14, 2026. Scripts embedded on customer sites served it for about four hours: 16:05 to 20:13 UTC according to Sansec, and 16:07 to 20:30 UTC according to Brevo.
How do I check if my WordPress site has the Web Media Optimizer backdoor?
Check wp-content/mu-plugins and wp-content/plugins on disk, not only the dashboard, because the plugin hides from the plugin list. Look in web server logs for September 14 plugin upload and activation requests. Search for “Web Media Optimizer”, sendibt1.com subdomains, and glegchner[.]com. Remove the plugin before you rotate admin passwords and sessions.
Would SRI or CSP have stopped the Brevo attack?
Subresource Integrity would have blocked the altered files, because the browser checks the bytes it receives against a pinned hash. Few sites pin vendor loaders, because vendors update them without notice. A strict Content Security Policy on your own pages could block the attacker’s new script domains. The attacker stripped CSP only from Brevo’s responses, and Sansec logged 2,549 CSP violation reports from 12 sites.
Is the Brevo SSO breach connected to the supply chain attack?
Brevo has not confirmed a link. On September 10, a SAML single sign-on flaw exposed 138 Brevo accounts: six sent phishing emails and 43 had contacts exported. Trezor said phishing from its account reached about 347,000 newsletter addresses. The September 14 attack used a different path: a Cloudflare API key that Brevo says was first misused in late August.
How can you detect a compromised third-party script?
Watch what the script does in a real browser, not only its file hash or timestamp. In the Brevo attack, origin files and Last-Modified dates never changed. Browser-side monitoring compares each script’s behavior to a baseline and flags new network destinations, new cookies, and new fourth-party sources. Reflectiz does this from outside your site, with no agent or code to install.
Subscribe to our newsletter
Stay updated with the latest news, articles, and insights from Reflectiz.
Related Articles
AI Has Changed The Web.
Are You Ready for What’s Next?
Third-party code shifts by the hour. Supply-chain compromises strike without warning. AI-driven web attacks now evolve faster than traditional security can ever keep up.
Reflectiz delivers the continuous, real-time visibility needed to expose the risks traditional tools miss entirely.
Zero code changes. Zero access to your data. Ultimate peace of mind.