
Brevo Supply Chain Attack: ClickFix and WordPress Backdoor Distributed via Compromised Scripts
Cybersecurity NewsCybersecurityWordPressSupply Chain AttackClickFixBackdoorBrevo
On September 14, 2026, Brevo scripts integrated into its clients' websites were compromised to distribute a ClickFix attack and a WordPress backdoor. This represents a supply chain attack where malicious code was injected through Brevo's scripts that were embedded on customer sites. The incident affected multiple Brevo clients whose websites were running the compromised scripts during the attack period.