#PushEngage
Bei einer Supply-Chain-Attacke installieren Angreifer Backdoors durch die WordPress-Plug-ins OptinMonster, TrustPulse und PushEngage. #Security
WordPress-Plug-ins: Lieferkettenangriff gefährdet 1,2 Millionen Seiten
Bei einer Supply-Chain-Attacke installieren Angreifer Backdoors durch die WordPress-Plug-ins OptinMonster, TrustPulse und PushEngage.
www.heise.de
June 16, 2026 at 10:05 AM
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN).
OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN).
www.bleepingcomputer.com
June 15, 2026 at 5:37 PM
Awesome Motive, one of the largest WordPress plugin devs, is dealing with a supply chain attack

Luckily this impacts only three of their smaller plugins

Seems to be under control now, but this planted backdoors in a lot of places

sansec.io/research/opt...
OptinMonster supply chain attack hits 1.2 million sites
Malware adds admin accounts and hidden backdoor to sites using OptinMonster, TrustPulse or PushEngage plugins.
sansec.io
June 14, 2026 at 1:05 AM
🚨 1.2M WordPress sites hit by a CDN supply chain attack on OptinMonster, TrustPulse, and PushEngage. No outdated plugins involved, just a compromised CDN key stealing admin nonces.

How to check + fix it:

devencyclopedia.com/blog/wordpre...

#wordpress #security
WordPress CDN Supply Chain Attack 2026: What Happened and How to Check Your Site
The OptinMonster, TrustPulse, and PushEngage supply chain attack (June 2026) hit 1.2M sites. Here's exactly how it worked, how to check if you were compromised, and how to recover.
devencyclopedia.com
June 22, 2026 at 3:55 AM
A supply chain attack compromised Awesome Motive's CDN, injecting malicious JavaScript into WordPress plugins OptinMonster, TrustPulse, and PushEngage. The attack, discovered by Sansec, allowed attackers to create backdoor admin accounts and exfiltrate sensitive data.
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
securityaffairs.com
June 16, 2026 at 7:32 AM
OptinMonster WordPressプラグインがCDNサプライチェーン攻撃によりハッキングされる
#CybersecurityNews
www.bleepingcomputer.com/news/securit...
OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN).
www.bleepingcomputer.com
June 17, 2026 at 4:37 AM
CDN Poisoning 20: How a 25-Minute Supply Chain Attack Compromised 12 Million WordPress Sites + Video

Introduction On June 13, 2026, security researchers at Sansec uncovered an active supply-chain attack that had silently compromised over 1.2 million WordPress sites. The attackers injected…
CDN Poisoning 20: How a 25-Minute Supply Chain Attack Compromised 12 Million WordPress Sites + Video
Introduction On June 13, 2026, security researchers at Sansec uncovered an active supply-chain attack that had silently compromised over 1.2 million WordPress sites. The attackers injected malicious JavaScript into legitimate files served through Awesome Motive's CDN endpoints, affecting three popular plugins—OptinMonster, TrustPulse, and PushEngage—all operated by one of the largest WordPress plugin companies in the world. What makes this attack particularly insidious is that the malware didn't reside on any victim's server; it was pulled directly from the vendor's trusted CDN, making it nearly invisible to traditional security monitoring.
undercodetesting.com
June 24, 2026 at 7:50 AM
Compare the best push notification software of 2026 — OneSignal, Braze, Airship, PushEngage and Firebase Cloud Messaging — across pricing, use cases and features, with direct links.
Best Push Notification Software in 2026: Features, Pricing & Comparison
Compare the best push notification software of 2026 — OneSignal, Braze, Airship, PushEngage and Firebase Cloud Messaging — across pricing, use cases and features, with direct links.
kurums.com
July 1, 2026 at 9:15 PM
Interesting. Is this to ward off or in response to employee strikes? Step in with testing where govts have failed? #COVID__19 https://chainstoreage.com/amazon-q1-sales-26-spend-entire-q2-operating-profit-covid-expenses?utm_source=PushEngage&utm_medium=push&utm_campaign=PushEngage
Amazon Q1 sales up 26%; to spend entire Q2 operating prof...
Amazon dropped a bombshell with its first-quarter earning...
chainstoreage.com
November 13, 2024 at 9:20 PM
OptinMonster, TrustPulse, and PushEngage were briefly hit in a CDN supply-chain attack, serving malicious JavaScript that could add rogue admins, hide backdoors, and enable remote access. #OptinMonster #TrustPulse #PushEngage
OptinMonster WordPress plugin hacked in CDN supply-chain attack
A supply-chain attack against Awesome Motive's CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage, briefly serving malicious JavaScript to users. Attackers used a stolen CDN API key to inject code that could create rogue administrator accounts, install hidden backdoors, and give full remote access to infected sites. #OptinMonster #TrustPulse #PushEngage #AwesomeMotive #UpdraftPlus
www.hendryadrian.com
June 15, 2026 at 8:00 PM
OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack
OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack
A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at Sansec discovered an ongoing campaign targeting plugins developed by Awesome Motive, including OptinMonster, TrustPulse, and PushEngage. These plugins are installed on millions of WordPress sites worldwide, with OptinMonster alone surpassing one million active installations. Rather than attacking individual websites directly, threat actors compromised upstream JavaScript files hosted on Awesome Motive’s CDN. Any website loading these scripts unknowingly executed the injected malware , making this attack comparable to previous large-scale supply chain incidents. The malicious payload is designed to remain stealthy and only activates when a WordPress administrator is logged in. It avoids execution in headless browsers and automated environments, significantly reducing the chances of detection during routine scans. OptinMonster Plugin Hack Exposes Once triggered, the script identifies the WordPress admin environment, gathers site metadata, and extracts authentication tokens from REST and AJAX endpoints. Using these tokens, the malware attempts to create unauthorized administrator accounts through multiple methods, including REST API calls and form submissions. The injected scripts were served through legitimate domains such as: a.omappapi.com a.opmnstr.com a.optnmstr.com a.trstplse.com clientcdn.pushengage.com It establishes persistence by deploying both a fixed account named developer_api1 and additional randomized accounts following the dev_xxxxxx pattern. The stolen credentials, along with site details, are encrypted and transmitted to a command-and-control server hosted on the domain tidio.cc, which mimics a legitimate service to evade suspicion. To maintain long-term access, the attackers install a hidden backdoor plugin that is engineered to evade detection. The plugin conceals itself from the WordPress dashboard, API responses, update mechanisms, and activity logs. It provides attackers with full remote control of compromised websites by enabling arbitrary command execution and remote code execution through specially crafted requests. Indicators of Compromise Organizations should check for the following: Suspicious domains : tidio.cc (84.201.6.54). Rogue admin accounts: developer_api1 or dev_xxxxxx. Hidden plugins: content-delivery-helper or database-optimizer. Unique string: jX9kM2nP4qR6sT8v (XOR key). Note : IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Sansec researchers observed that the plugin frequently changes its disguise, appearing as legitimate tools such as “Content Delivery Helper” or “Database Optimizer.” Active exploitation has been confirmed, with Patchstack blocking hundreds of attempts to create rogue administrator accounts across multiple sites, indicating real-world abuse of the backdoor. According to Awesome Motive, the incident was caused by the exploitation of a vulnerability in the UpdraftPlus plugin. Attackers reportedly gained access to a server hosting marketing infrastructure, retrieved a CDN API key, and used it to inject malicious code into files distributed to customers. The company has since removed the malicious scripts, rotated credentials, purged CDN caches, and migrated affected systems to new infrastructure. Administrators using the affected plugins are strongly advised to assume potential compromise if a logged-in admin session occurred during the attack window. Immediate steps should include auditing all administrator accounts for unauthorized entries, scanning the filesystem directly for hidden plugins, and rotating all credentials. Since the malware activates only during authenticated admin sessions, server-side inspection remains one of the most effective detection methods. This incident highlights the growing threat of supply chain attacks in the WordPress ecosystem, where compromising a single trusted source can lead to widespread impact across millions of websites. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack appeared first on Cyber Security News .
cybersecuritynews.com
June 16, 2026 at 8:00 AM
OptinMonster WordPress plugin hacked in CDN supply-chain attack
OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN).
www.bleepingcomputer.com
June 15, 2026 at 5:48 PM
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage.
securityaffairs.com
June 15, 2026 at 9:59 AM
OptinMonster hackeado: 1,4M sitios en riesgo (junio 2026)

Ataque cadena suministro OptinMonster del 12/6/2026: CDN de Awesome Motive comprometido, 1,4M sitios expuestos. ¿Tu sitio tiene usuarios rogue o backdoo...

#supplychain #optinmonster #cdncomprometido #updraftpluscve #wordpressmalware
Ataque cadena suministro OptinMonster afecta 1.2M - Seguridad en Wordpress
Más de 1.2 millones de sitios WordPress recibieron código malicioso desde el CDN oficial de Awesome Motive. El ataque a OptinMonster, TrustPulse y PushEngage crea cuentas admin ocultas e instala backdoors invisibles desde el dashboard.
seguridadenwordpress.com
July 1, 2026 at 5:18 AM
Ataque cadena suministro OptinMonster afecta 1.2M

¿Tenés OptinMonster, TrustPulse o PushEngage? Un ataque de cadena de suministro inyectó malware desde el CDN oficial de Awesome Motive en junio de 2026....

#optinmonster #cadenasuministro #wordpress #malware #awesomemotive
Ataque cadena suministro OptinMonster afecta 1.2M - Seguridad en Wordpress
Más de 1.2 millones de sitios WordPress recibieron código malicioso desde el CDN oficial de Awesome Motive. El ataque a OptinMonster, TrustPulse y PushEngage crea cuentas admin ocultas e instala backdoors invisibles desde el dashboard.
seguridadenwordpress.com
June 16, 2026 at 12:35 AM
WPVibe Brings AI to WordPress + Smarter Automations, SEO, & Fundraising Tools

WPVibe launched on WordPress.org, and with it, something genuinely new: the ability to manage your entire WordPress site through a simple conversation with AI. No dashboard, no switching tabs. Just tell Claude or ChatGPT…
WPVibe Brings AI to WordPress + Smarter Automations, SEO, & Fundraising Tools
WPVibe launched on WordPress.org, and with it, something genuinely new: the ability to manage your entire WordPress site through a simple conversation with AI. No dashboard, no switching tabs. Just tell Claude or ChatGPT what you want done, and it happens. That’s the headline, but there’s plenty more to cover. AIOSEO, Charitable, PushEngage, OptinMonster, and others all shipped significant updates. WordCamp Asia brought the global community together in Mumbai.
toolcome.com
April 30, 2026 at 10:50 AM
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
securityaffairs.com/193616/malwa...
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage.
securityaffairs.com
June 15, 2026 at 12:15 PM
Supply-Chain Attack Compromises OptinMonster, TrustPulse, and PushEngage WordPress Plugins

A supply-chain attack targeting the content delivery network (CDN) of software publisher Awesome Motive exposed users of several popular WordPress marketing plugins to malicious code, according to findings…
Supply-Chain Attack Compromises OptinMonster, TrustPulse, and PushEngage WordPress Plugins
A supply-chain attack targeting the content delivery network (CDN) of software publisher Awesome Motive exposed users of several popular WordPress marketing plugins to malicious code, according to findings from e-commerce security firm Sansec.
www.abijita.com
June 16, 2026 at 1:26 AM
OptinMonster WordPress plugin hacked in CDN supply-chain attack

WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]
#hackernews #news
OptinMonster WordPress plugin hacked in CDN supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]
www.bleepingcomputer.com
June 16, 2026 at 6:27 PM
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites.

When a site administr…
#hackernews #news
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened a way back in. Ordinary visitors did not trigger it
thehackernews.com
June 15, 2026 at 11:31 PM
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN

Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage. Sansec researchers discovered an active supply chain attack hitting WordPres…
#hackernews #news
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage. Sansec researchers discovered an active supply chain attack hitting WordPress sites running OptinMonster, TrustPulse, and PushEngage, three plugins operated by Awesome Motive, one of the largest WordPress plugin companies in the world. The malicious JavaScript wasn’t sitting on any victim’s server. […]
securityaffairs.com
June 15, 2026 at 11:21 PM