Supply-Chain Attack Compromises WordPress Plugins OptinMonster, TrustPulse, PushEngage (infosecurity-magazine.com)
- Supply-chain attack on WordPress plugins OptinMonster, TrustPulse, and PushEngage.
- Tampered JavaScript served via Awesome Motive's CDN, affecting up to 1.2 million sites.
- Payload activates on admin login, creating rogue admin and backdoor.
- Exposure window short: OptinMonster and TrustPulse compromised for ~30 min on June 12; PushEngage still compromised on June 13.
- Entry point unknown; Awesome Motive's own servers or CDN account suspected.
"On June 13, 2026, Dutch security firm Sansec disclosed a supply-chain attack affecting WordPress plugins OptinMonster, TrustPulse, and PushEngage, all developed by Awesome Motive. The attackers tampered with JavaScript served via Awesome Motive's delivery network, potentially affecting up to 1.2 million sites. The payload creates a rogue administrator account and installs a hidden backdoor plugin when an admin is logged in. The exposed windows were short: OptinMonster and TrustPulse were compromised for about half an hour on June 12, while PushEngage was still serving malware on June 13. How the attackers gained access remains unclear."
no comments yet.