CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6280

As cited

Copy frozen at (site build).

breaches incidents

Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins

Attackers compromised content delivery network (CDN) servers for OptinMonster, TrustPulse, and PushEngage marketing plugins, injecting malicious JavaScript into their SDKs between June 12 and June 14, 2026. The injected code ran in administrators' browsers with valid sessions and nonces to silently create rogue admin accounts and deploy self-hiding backdoor plugins. Over 1.2 million WordPress sites were potentially exposed, and Patchstack's firewall blocked 271 exploitation attempts across 13 sites during the incident.

Why it matters: WordPress site administrators and hosting providers using these three Awesome Motive plugins must immediately audit for rogue accounts (developer_api1, dev_xxxxxx patterns), hidden backdoor plugins, and rotated credentials, because compromised sites remain vulnerable until manually cleaned, and the malicious requests were indistinguishable from legitimate admin activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins

Attackers compromised content delivery network (CDN) servers for OptinMonster, TrustPulse, and PushEngage marketing plugins, injecting malicious JavaScript into their SDKs between June 12 and June 14, 2026. The injected code ran in administrators' browsers with valid sessions and nonces to silently create rogue admin accounts and deploy self-hiding backdoor plugins. Over 1.2 million WordPress sites were potentially exposed, and Patchstack's firewall blocked 271 exploitation attempts across 13 sites during the incident.

Why it matters: WordPress site administrators and hosting providers using these three Awesome Motive plugins must immediately audit for rogue accounts (developer_api1, dev_xxxxxx patterns), hidden backdoor plugins, and rotated credentials, because compromised sites remain vulnerable until manually cleaned, and the malicious requests were indistinguishable from legitimate admin activity.

VendorsMicrosoftAppleGoogleWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary