CTIPilot

Brevo Cloudflare Worker / ClickFix supply-chain compromise (September 2026)

incident · incident:brevo-cloudflare-worker-clickfix-supply-chain-2026-09

A stolen, hardcoded long-lived Cloudflare API key let an attacker deploy a malicious Cloudflare Worker rewriting Brevo's own pages and customer-embedded widget scripts at the CDN edge for roughly 5.5 hours on 2026-09-14, serving ClickFix malware and a WordPress admin backdoor plugin to up to 100,000 sites, without modifying any origin file (Brevo, Sansec, 2026-09-17).

Coverage timeline
1
first 2026-09-18 → last 2026-09-18
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
4
pinned v19.2 · see below

Hunting pivots

Affected products

ATT&CK techniques

4 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-18/brevo-cloudflare-worker-clickfix-supply-chain · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-09-18/brevo-cloudflare-worker-clickfix-supply-chain · ATT&CK page ↗

Execution TA0002

T1204.004User Execution: Malicious Copy and Paste×1

An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.

Evidence: 2026-09-18/brevo-cloudflare-worker-clickfix-supply-chain · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-18/brevo-cloudflare-worker-clickfix-supply-chain · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-18/brevo-cloudflare-worker-clickfix-supply-chain · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-18/brevo-cloudflare-worker-clickfix-supply-chain · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-09-18/brevo-cloudflare-worker-clickfix-supply-chain · ATT&CK page ↗

Story timeline

  1. 2026-09-18Brevo: a stolen, hardcoded Cloudflare API key let an attacker inject ClickFix malware and a WordPress backdoor plugin via a CDN-edge Worker into up to 100,000 customer sites, defeating origin-side integrity checks
    active-threatsBrevo's own integrity checks never saw the tampering because the attacker rewrote pages at Cloudflare's edge, not on Brevo's servers

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (33%)
  • sansec.io1 (33%)
  • status.brevo.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Brevo Cloudflare Worker / ClickFix supply-chain compromise (September 2026) (1)

2026-09-18 · view entry permalink →

HIGHNATOA1

Brevo: a stolen, hardcoded Cloudflare API key let an attacker inject ClickFix malware and a WordPress backdoor plugin via a CDN-edge Worker into up to 100,000 customer sites, defeating origin-side integrity checks

Brevo (CRM/email-marketing platform, formerly Sendinblue) confirmed in a 2026-09-17 post-mortem that an attacker used a long-lived Cloudflare API key with full account permissions, hardcoded in Brevo's application source code, to create a malicious Cloudflare Worker on Brevo's own account, first misused as early as late August 2026 (Brevo, 2026-09-17). Brevo's own stated impact window ran 15:01 to 20:30 UTC on 2026-09-14 (5 hours 29 minutes), during which the Worker rewrote HTTP responses at the CDN edge on brevo.com and related domains, stripping security headers such as Content-Security-Policy; from 16:07 UTC the Worker additionally appended a malicious loader to three JavaScript files, the Brevo forms script, the Conversations widget and the SDK loader, that customers embed directly on their own sites, and extended the tampering to sibforms.com (Brevo, 2026-09-17). Because the edge rewrite never touched an origin file, Brevo's own standard integrity checks did not detect the change (Brevo, 2026-09-17). Visitors saw a fake Cloudflare human-verification page instructing them to press Win+R, paste and press Enter, a ClickFix lure that ran an attacker-supplied clipboard command to download Windows malware (Brevo, 2026-09-17), and did not activate for crawlers, developers or automated scanners (Sansec, 2026-09-16). On WordPress sites embedding an affected widget, a logged-in administrator's browser silently installed a plugin impersonating "Web Media Optimizer" that hides itself from the plugin list, persists via the must-use-plugins directory, beacons to an attacker server for a Base64-encoded next-stage JavaScript URL, caches the last-valid URL as a fallback, and carries a hardcoded authentication key that lets the attacker generate a valid WordPress-administrator login session without the account password (BleepingComputer, 2026-09-17). Sansec independently corroborated the root cause before Brevo's own confirmation, matching Last-Modified timestamps across injected and clean asset versions and finding an SSL certificate for the attacker's infrastructure issued 2026-08-25, pinning the attacker's access to at least that date (Sansec, 2026-09-16); Sansec estimates the affected embedded-script exposure reached up to 100,000 sites (Sansec, 2026-09-16), an upper-bound count of sites embedding the affected components, not a confirmed count of sites whose visitors received the payload. Brevo's post-mortem does not mention a separate SSO-hijacking incident it disclosed on 2026-09-10 that BleepingComputer reports led to a phishing campaign against Trezor customers, and BleepingComputer states Brevo did not respond to its question about whether the two incidents were connected (BleepingComputer, 2026-09-17).

Triage: a legitimate Brevo or Sendinblue widget script served from its normal CDN path is expected; the discriminator here is behavioral, not path-based; a fake human-verification overlay instructing a clipboard-paste-and-run action is never legitimate CDN content, and any WordPress site should treat a plugin absent from its own admin plugin list, yet present in the must-use-plugins directory, as compromised.

A long-lived Cloudflare API key with full account permissions was stored in application source code and was obtained by the attacker. With it, they could create Workers, routes and DNS records on Brevo's zones without triggering an alert.

Because the Worker rewrote responses at the edge and removed security headers such as Content-Security-Policy, our origin servers and files remained unmodified and standard integrity checks did not detect the change.

Brevo 2026-09-17

The plugin also stores a backup copy of the last valid JavaScript URL so it can continue loading malicious code if the remote server becomes unavailable.

the plugin contains a hardcoded authentication key that allows attackers to generate a valid login session for a WordPress administrator account without knowing the account password.

BleepingComputer 2026-09-17
incident18 Sep 05:02Zmulti-sourceOpen finding ↗