Malicious Brevo Widgets Compromise Over 100,000 Sites, Distribute Malware via WordPress Forms
A widespread supply‑chain breach linked to the email‑marketing platform Brevo has turned the service's public widgets into a conduit for malware, affecting more than 100,000 websites that embed the company's JavaScript assets.
Security researchers discovered that attackers hijacked a range of Brevo‑hosted resources—including signup forms, unsubscribe pages and live‑chat widgets—to inject malicious code. Because these assets are loaded from Brevo’s own servers, any site that incorporates them automatically pulls in the compromised script, exposing both site visitors and administrators to the payload without any direct interaction with the attacker.
The bulk of the affected sites run on WordPress, a platform that frequently relies on third‑party plugins and external widgets for functionality. By targeting the Brevo widgets that many WordPress themes and plugins embed by default, the threat actors achieved a high‑impact distribution method with minimal effort. Administrators reported seeing unexpected redirects and the appearance of unfamiliar files in their installations after the malicious script executed.
While the exact nature of the delivered malware remains under investigation, preliminary analysis suggests it is designed to establish a foothold on compromised hosts, potentially enabling further malicious activity such as data exfiltration or the installation of additional payloads. The attack exemplifies a classic supply‑chain model, where compromising a trusted third‑party service can cascade to thousands of downstream sites.
Brevo has acknowledged the incident, confirming that a “security incident” was detected on its infrastructure and that remediation steps are underway. The company has removed the malicious code from its servers, issued advisories to customers, and is working with security firms to understand the scope of the breach. Independent researchers have begun scanning the web for remnants of the compromised widgets, urging site owners to verify that they are loading the latest, clean versions of Brevo assets.
Experts recommend that website operators audit any third‑party scripts, enforce strict content‑security policies, and monitor network traffic for anomalous requests to external domains. As the investigation continues, the incident serves as a reminder that even widely trusted services can become vectors for large‑scale attacks, highlighting the need for continuous vigilance in supply‑chain security.
Comments (0)
Be the first to comment.
Join the discussion