Attackers used a stolen, long-lived Cloudflare API key with full account permissions to deploy a malicious Cloudflare Worker across Brevo zones. On September 14, the Worker rewrote CDN-edge responses, removed security headers, and injected malicious JavaScript into Brevo pages and customer sites using Brevo tracker, chat-widget, and hosted-form assets. The activity used attacker-controlled cdn*.sendibt1.com infrastructure and may have exposed more than 100,000 websites over roughly four to five-and-a-half hours.
Visitors to affected sites received ClickFix social-engineering overlays designed to persuade them to copy and execute malicious commands, while logged-in WordPress administrators were targeted with attempted installation of a persistent, unknown plugin. Brevo removed the Worker, revoked exposed credentials, eliminated hardcoded secrets and attacker-controlled hostnames, and purged edge caches; it said its application, API, mail-delivery infrastructure, and customer-account data were not affected. Organizations using Brevo web assets should investigate for unauthorized WordPress plugins and assess endpoints where users may have followed the ClickFix prompts.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
All identified malicious cdn*.sendibt1.com hosts stopped resolving, and Brevo origin-hosted assets were reported clean. Sansec advised affected organizations to investigate WordPress installations and endpoints whose users followed the ClickFix prompt.
The injected payload attempted to upload a malicious WordPress plugin when it detected a logged-in administrator; the plugin was designed for persistence and could load further JavaScript. Other visitors received a fake Cloudflare verification overlay using ClickFix instructions to induce Windows users to run a command.
Attackers abused a stolen, full-permission Cloudflare API key to deploy a malicious Worker that rewrote Brevo CDN-edge responses from approximately 16:07 to 20:30 UTC. The Worker removed security headers and injected malicious JavaScript into Brevo sites and customer-embedded forms, chat widgets, and SDK loaders, potentially affecting more than 100,000 sites.
Brevo disclosed a separate incident involving abuse of a SAML SSO flaw affecting 138 customer accounts. Brevo said the attacker lost access at 08:30 UTC that day.
A TLS certificate for cdn.sendibt1.com was created, indicating the attacker-used subdomain existed before the later supply-chain attack.
Brevo removed the malicious Cloudflare Worker and routes, revoked the exposed API key and credentials created with it, removed the hardcoded secret, deleted attacker-controlled hostnames, and purged edge caches. It stated that its application, API, mail-delivery infrastructure, and customer-account data were unaffected.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.