
Brevo — the digital marketing and CRM platform formerly known as Sendinblue — confirmed on September 17 that attackers used a stolen Cloudflare API key to mount a supply-chain attack on September 14. The key, which had been hardcoded in Brevo’s application source code with full account permissions, allowed the attackers to create a malicious Cloudflare Worker that silently rewrote responses at the CDN edge. Because the modification happened at the edge, Brevo’s origin servers were untouched and standard file-integrity checks saw nothing. The window of exposure ran from 16:07 to 20:30 UTC — about five and a half hours.
During that window, the Worker injected ClickFix scripts into pages on brevo.com, sendinblue.com, and the Brevo Forms, Conversations, and SDK Loader scripts that customers embed on their own sites. Security firm Sansec estimates up to 100,000 websites loaded the compromised scripts. Visitors saw a fake Cloudflare browser verification prompt, followed by ClickFix instructions urging them to run a Windows command — the classic paste-and-execute malware delivery technique. For WordPress site owners who visited any affected page while logged in as an administrator, the script also attempted to install a malicious plugin called “Web Media Optimizer,” which hides from the plugin list, copies itself to the must-use plugins folder for persistence, and includes a backdoor credential that lets the attacker log in as an admin without knowing the real password. Brevo says its API, email delivery infrastructure, and customer account data were not affected, and all malicious subdomains stopped resolving by September 15. This is a separate incident from a September 10 SSO breach at Brevo that was used to launch phishing attacks against the email lists of Brevo customers, including Trezor, whose users were exposed.
How to check if you’re affected
Affected products include any WordPress site that embedded a Brevo Forms widget, Brevo Conversations widget, or Brevo SDK Loader between 16:07 and 20:30 UTC on September 14, 2026. WordPress administrators who were logged in and visited an affected site during that window should check the Plugins list for any unfamiliar plugin installed or activated on September 14 — particularly one named “Web Media Optimizer” or similar. If found, deactivate and delete it, check the mu-plugins directory (usually at wp-content/mu-plugins/) for leftover copies, and rotate all administrator passwords immediately.
