ClickFix backdoor distributed via Brevo supply-chain attack on WordPress sites
A supply-chain attack on Brevo compromised a Cloudflare API key, allowing attackers to inject malicious ClickFix scripts into customer websites. The attack affected Brevo's domains and embedded scripts, leading to the distribution of a malicious WordPress plugin named 'Web Media Optimizer' that acts as a backdoor. The plugin communicates with an attacker-controlled server and can generate valid login sessions for WordPress administrators. The attack was active between September 14 and 15, 2026, and affected up to 100,000 websites.
- First seen
- 2026-09-14
- Last seen
- 2026-09-17
- Threat actors
- —
- Malware
- ClickFix, Web Media Optimizer
- Sectors
- Technology
- Countries
- United States
How it works
Attackers compromised a Cloudflare API key, enabling them to inject malicious ClickFix scripts into Brevo's customer websites. These scripts were used to distribute a malicious WordPress plugin named 'Web Media Optimizer,' which acts as a backdoor. The plugin communicates with an attacker-controlled server and can generate valid login sessions for WordPress administrators, allowing further access and control.
Techniques (MITRE ATT&CK)
- T1530 · collectionData from Cloud StorageAttackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites.
- T1548 · privilege_escalationAbuse Elevation Control MechanismThe plugin contains a hardcoded authentication key that allows attackers to generate a valid login session for a WordPress administrator account.
Indicators
Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.
- glegchner.com
- cdn10.sendibt1.com
- yelahaye.surf
- boiseno.club
- https://cdn10.sendibt1.com/p/wm.zip
What to do
- Hunt for the malicious 'Web Media Optimizer' plugin on WordPress sites.
- Verify exposure to the compromised Brevo components and Cloudflare Worker.
- Prioritize patching Cloudflare API key management practices.
- Block the attacker-controlled domains: glegchner[.]com, cdn10.sendibt1[.]com, yelahaye[.]surf, and boiseno[.]club.
- Review and rotate administrator passwords for WordPress sites that may have been affected.