discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

OptinMonster WordPress plugin hacked in CDN supply-chain attack

OptinMonster and TrustPulse plugins compromised in CDN supply-chain attack. Awesome Motive's CDN used by OptinMonster, TrustPulse, and PushEngage impacted.

By Bill Toulas·Jun 15·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

OptinMonster WordPress plugin hacked in CDN supply-chain attack
Image: bleepingcomputer.com

OptinMonster WordPress plugin compromised in a CDN supply-chain attack. Attackers gained access through UpdraftPlus flaw to steal credentials for CDN account and modify JavaScript files.

Why it matters

This highlights the vulnerability of popular plugins like OptinMonster when they are hosted on compromised CDNs, emphasizing the importance of secure third-party integrations.

Some bad guys tricked a company into letting them use their website. The bad guys put some sneaky code on the site that let them take over other people's accounts. Now they're trying to steal information from websites using popular tools like OptinMonster. They fixed it by changing where the sneaky code is stored.

Analysis

Background

OptinMonster, TrustPulse, and PushEngage are WordPress lead-generation and conversion optimization platforms. The attack leveraged a known flaw in UpdraftPlus to gain access to Awesome Motive's CDN server hosting marketing websites.

Attack Details

Awesome Motive discovered the compromised CDN on June 12th. The malicious scripts were served for a short period, affecting OptinMonster and TrustPulse users. PushEngage continued serving malicious JavaScript code until June 13th.

Malware Functionality

The malware triggered when an administrator visited an infected website, collecting authentication tokens and nonces to create a rogue admin account. The attackers installed a self-hiding backdoor plugin and established communication with a domain impersonating Tidio for data exfiltration.

Remediation Steps

Awesome Motive remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key. They assured that their application servers, source code, and plugin hosting servers were not compromised.

Recommendations for Affected Users

Site owners are advised to check for rogue admin accounts, inspect wp-content/plugins for hidden backdoor plugins, execute malware scans, rotate passwords, API keys, database credentials, and WordPress security salts.

Key points

  • OptinMonster and TrustPulse plugins were compromised
  • Attackers gained access through a known flaw in UpdraftPlus
  • Malware triggered when administrators visited infected websites
  • Affected users were advised to check for rogue admin accounts, inspect wp-content/plugins for hidden backdoor plugins, execute malware scans, rotate passwords, API keys, database credentials, and WordPress security salts
The Upside

With this incident, security teams are learning and improving their detection methods. This will help catch similar attacks in the future.

The Downside

The attack shows that even popular plugins can be vulnerable if they're hosted on compromised servers. It's important for developers to ensure secure third-party integrations.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpresssupply-chaincdnmalware

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Jun 15, 2026

Source

bleepingcomputer.com

Share

Topics

securitywordpresssupply-chaincdnmalware

Related

More from this desk

Aug 26·bleepingcomputer.com

Critical Avada WordPress theme flaw enables zero-click RCE

Critical vulnerability in Avada WordPress theme can be exploited for arbitrary PHP code execution. CVE-2026-18431 affects Avada versions up to 7.16 and Fusion Builder plugin versions up to 3.16.

Aug 26·bleepingcomputer.com

New GPUThor attack defeats NVIDIA ECC protection for root access

Researchers demonstrate a new Rowhammer attack called GPUThor that can bypass ECC protections on NVIDIA GPUs, leading to DoS and privilege escalation.

Aug 26·thehackernews.com

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI disrupts QTFY hacking platforms used by Chinese threat actors to target U.S. critical infrastructure and sensitive networks.

Aug 26·bleepingcomputer.com

Boston Scientific Announces Cyberattack Disrupts Global Operations

Boston Scientific reports a cyberattack that disrupted its IT systems, causing operational disruptions globally. The company is working to restore affected functions and systems access.