Awesome Motive CDN breach injected malware into OptinMonster, TrustPulse, and PushEngage WordPress plugins

Attackers compromised Awesome Motive's content delivery network and briefly pushed malicious code to websites using OptinMonster, TrustPulse, and PushEngage, putting those sites at risk of takeover. According to Awesome Motive and Sansec, the attackers first breached a marketing server by exploiting a known flaw in the UpdraftPlus WordPress plugin, stole a CDN API key, and altered JavaScript served from Awesome Motive CDN domains. The malicious code activated when a WordPress administrator loaded a page, stole authentication tokens and nonces, created rogue admin accounts, and installed hidden backdoor plugins that enabled arbitrary PHP code execution and web-shell access.
Why it matters: Website owners using these plugins may still have hidden attacker access even though the malicious CDN files were removed. Administrators should immediately check for rogue admin users and unknown plugins, rotate passwords and keys, and scan affected WordPress servers for persistence.

Sources

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
SecurityWeek News 2026.06.19 95% relevant
This source adds a stronger scope estimate, saying the compromised OptinMonster, TrustPulse, and PushEngage CDN scripts may have affected more than 1.2 million WordPress sites, and repeats the attacker path via a compromised UpdraftPlus instance and CDN key.
OptinMonster WordPress plugin hacked in CDN supply-chain attack
Bill Toulas 2026.06.15 100% relevant
This article appears to be the first clear report establishing the underlying event: a CDN-level supply-chain attack on Awesome Motive plugin assets that led to website compromise.
← Back to all stories