Brevo supply-chain attack injected ClickFix scripts on customer sites
8 Articles
8 Articles
Hack at Marketing Vendor Exploited To Widely Spread ClickFix Malware Attack
A hack at Brevo, an online marketing vendor, created a pathway to place a ClickFix-style attack across numerous websites on Monday to try and trick users into installing malware.
Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
An attack on Brevo exposed thousands of sites to ClickFix malware and installed a backdoor on WordPress blogs. See how to protect your site.
On Monday, September 14, 2026, hackers hijacked a Cloudflare key from Brevo, the ex-Sendinblue, to drag malicious code into resources recovered by more than 100,000 sites. This is the second security incident in five days for this French emailing platform.
Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites
A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators. The activity reached more than 100,000 customer sites on September 14, according to the investigation. People who opened affected sites, chat features, sign-up forms, or email-linked unsubscribe …
Coverage Details
Bias Distribution
- 50% of the sources lean Left, 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









