OptinMonster WordPress plugin hacked in CDN supply-chain attack
OptinMonster and TrustPulse plugins compromised in CDN supply-chain attack. Awesome Motive's CDN used by OptinMonster, TrustPulse, and PushEngage impacted.
Intelligence analysis by Qwen 2.5 (3B)

OptinMonster WordPress plugin compromised in a CDN supply-chain attack. Attackers gained access through UpdraftPlus flaw to steal credentials for CDN account and modify JavaScript files.
Some bad guys tricked a company into letting them use their website. The bad guys put some sneaky code on the site that let them take over other people's accounts. Now they're trying to steal information from websites using popular tools like OptinMonster. They fixed it by changing where the sneaky code is stored.
Analysis
Background
OptinMonster, TrustPulse, and PushEngage are WordPress lead-generation and conversion optimization platforms. The attack leveraged a known flaw in UpdraftPlus to gain access to Awesome Motive's CDN server hosting marketing websites.
Attack Details
Awesome Motive discovered the compromised CDN on June 12th. The malicious scripts were served for a short period, affecting OptinMonster and TrustPulse users. PushEngage continued serving malicious JavaScript code until June 13th.
Malware Functionality
The malware triggered when an administrator visited an infected website, collecting authentication tokens and nonces to create a rogue admin account. The attackers installed a self-hiding backdoor plugin and established communication with a domain impersonating Tidio for data exfiltration.
Remediation Steps
Awesome Motive remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key. They assured that their application servers, source code, and plugin hosting servers were not compromised.
Recommendations for Affected Users
Site owners are advised to check for rogue admin accounts, inspect wp-content/plugins for hidden backdoor plugins, execute malware scans, rotate passwords, API keys, database credentials, and WordPress security salts.
Key points
- OptinMonster and TrustPulse plugins were compromised
- Attackers gained access through a known flaw in UpdraftPlus
- Malware triggered when administrators visited infected websites
- Affected users were advised to check for rogue admin accounts, inspect wp-content/plugins for hidden backdoor plugins, execute malware scans, rotate passwords, API keys, database credentials, and WordPress security salts
With this incident, security teams are learning and improving their detection methods. This will help catch similar attacks in the future.
The attack shows that even popular plugins can be vulnerable if they're hosted on compromised servers. It's important for developers to ensure secure third-party integrations.



