As cited
Copy frozen at (site build).
breaches incidents
Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins
Attackers compromised content delivery network (CDN) servers for OptinMonster, TrustPulse, and PushEngage marketing plugins, injecting malicious JavaScript into their SDKs between June 12 and June 14, 2026. The injected code ran in administrators' browsers with valid sessions and nonces to silently create rogue admin accounts and deploy self-hiding backdoor plugins. Over 1.2 million WordPress sites were potentially exposed, and Patchstack's firewall blocked 271 exploitation attempts across 13 sites during the incident.
Why it matters: WordPress site administrators and hosting providers using these three Awesome Motive plugins must immediately audit for rogue accounts (developer_api1, dev_xxxxxx patterns), hidden backdoor plugins, and rotated credentials, because compromised sites remain vulnerable until manually cleaned, and the malicious requests were indistinguishable from legitimate admin activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins
Attackers compromised content delivery network (CDN) servers for OptinMonster, TrustPulse, and PushEngage marketing plugins, injecting malicious JavaScript into their SDKs between June 12 and June 14, 2026. The injected code ran in administrators' browsers with valid sessions and nonces to silently create rogue admin accounts and deploy self-hiding backdoor plugins. Over 1.2 million WordPress sites were potentially exposed, and Patchstack's firewall blocked 271 exploitation attempts across 13 sites during the incident.
Why it matters: WordPress site administrators and hosting providers using these three Awesome Motive plugins must immediately audit for rogue accounts (developer_api1, dev_xxxxxx patterns), hidden backdoor plugins, and rotated credentials, because compromised sites remain vulnerable until manually cleaned, and the malicious requests were indistinguishable from legitimate admin activity.
- Source published
- First seen by Cybersecurity Tracker