"Because the Worker rewrote responses at the edge and removed security headers such as Content-Security-Policy, our origin servers and files remained unmodified and standard integrity checks did not detect the change," Brevo explained.
How attackers abused a Cloudflare API key
Brevo confirmed attackers stole a long‑lived Cloudflare API key that had full account permissions and was hardcoded in application source code. With that key the adversary created a malicious Cloudflare Worker, routes, and DNS records across Brevo’s zones and used the Worker to modify content at the CDN edge. Brevo says the Worker’s modifications removed security headers and therefore left origin servers and files untouched, causing standard integrity checks to miss the tampering.
The ClickFix lure and the Web Media Optimizer plugin
Visitors to sites loading Brevo’s compromised scripts were redirected through a fake Cloudflare verification page and shown ClickFix instructions urging them to run a Windows command. On WordPress sites embedding affected Brevo widgets the injected script also checked whether the visitor was logged in as an administrator and attempted to upload a malicious archive from https://cdn10.sendibt1[.]com/p/wm.zip.
BleepingComputer located the archive on VirusTotal and reports it poses as a WordPress plugin named "Web Media Optimizer" while acting as a persistent backdoor and JavaScript loader. BleepingComputer observed that the plugin hides from the plugin list, copies itself into WordPress’s must‑use plugins directory for persistence, and periodically contacts an attacker‑controlled server at https://glegchner.com/ads.php.
That server currently returns a Base64‑encoded URL which decodes to https://corralos[.]beer/a412dkoq.js; that JavaScript delivers the ClickFix lure. The malicious plugin also stores a backup copy of the last valid JavaScript URL to maintain functionality if the remote server becomes unavailable, and it contains a hardcoded authentication key that allows attackers to generate a valid login session for a WordPress administrator account without knowing the account password.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleScope, timeline, and varying windows reported
Security firm Sansec first reported the incident and estimated it may have impacted up to 100,000 websites that use the affected Brevo components. Sansec dated the start of activity to September 14, 2026, between 16:05 and 20:13 UTC, and later confirmed malicious subdomains stopped resolving on September 15. Brevo reported the Worker modified content at the CDN edge for approximately five and a half hours on September 14; after detecting the compromise the company defined the exposure window as between 16:07 and 20:30 UTC.
Remediation steps Brevo reports taking
Brevo says that upon detecting the compromise it removed the malicious Worker and its routes, revoked the compromised API key and credentials created with it, removed the hardcoded credential from source code, deleted attacker‑controlled hostnames, and purged edge caches. The company also stated that app.brevo.com, its API, email delivery infrastructure, and customer account data were not affected.
What this means for WordPress administrators, enterprise customers, and end users
- WordPress administrators: If you visited an affected site while logged in on September 14, check for unusual plugins installed or activated on that date and remove them; rotate administrator passwords if any suspicious plugin is found.
- Enterprise customers that embed Brevo scripts: Monitor for unexpected modifications at the CDN edge, validate third‑party script integrity beyond origin file checks, and ensure no long‑lived, full‑permission API keys are hardcoded into application source code.
- End users and site visitors: If you followed the ClickFix instructions or ran commands offered by the lure, treat that activity as potentially compromising and follow incident response guidance from your administrator or security provider.
This incident combines a supply‑chain delivery mechanism — compromised loader scripts embedded by customers — with edge‑level manipulation through a cloud provider API key. Brevo disclosed an earlier, separate SSO‑related incident on September 10 in which attackers hijacked customer accounts and launched phishing against customers of companies using Brevo; one reported victim, Trezor, said on September 11 that phishing reached 347,000 user email addresses and compromised at least 2,500. Brevo did not answer questions about whether the September 10 SSO incident and the Cloudflare key compromise were connected.
The immediate facts are clear: a long‑lived, fully privileged API key duplicated in source code allowed an attacker to change what visitors saw at the CDN edge without altering origin files. The longer‑term questions — how the key was exposed, whether other long‑lived credentials exist in source, and whether the two September incidents share roots — are the next items that customers, investigators, and defenders will need to resolve.




