Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
An attacker tampered with JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, creating a hidden backdoor. Sites that loaded the malicious script should be treated as compromised.
Intelligence analysis by Llama 3.3 70B

The attacker used the tampered scripts to create an admin account and install a hidden plugin, allowing for remote access and control.
Someone hacked into popular WordPress plugins, making it possible for them to take control of websites. This is like having a secret key to a house, and the hacker can use it to get in and do bad things.
Analysis
The attack worked by using a poisoned script that did nothing on a normal page view but acted when a logged-in WordPress administrator loaded it, using that admin's session to take over. The script created a new admin account under the attacker's control and installed a plugin that does not show up in the dashboard, sending the new login details and site information to a fake domain. The hidden plugin opens a web shell, allowing the attacker to run code on the server without logging in, and can be used to read or change any file, copy the database, plant more backdoors, inject card-skimming code, redirect visitors, or steal data. The attacker got in by breaking into the server running PushEngage's marketing website, through a known flaw in UpdraftPlus, a WordPress backup plugin, and used a CDN API key to change the files delivered to customer sites. However, the entry point is still disputed, with Sansec saying the breached system is still unknown. Site administrators should assume their site is compromised if they used any of the three plugins during the attack window and take immediate action to check for indicators of compromise and clean their site.
Key points
- The attack affected PushEngage, OptinMonster, and TrustPulse plugins
- The malicious script created a hidden admin account and installed a plugin
- The attack can be used to read or change any file, copy the database, or steal data
- The entry point is still disputed, with a possible flaw in UpdraftPlus
- Site administrators should assume their site is compromised and take immediate action
The affected plugins' developers are working to resolve the issue, and site administrators can take steps to check for and remove the malicious code. With prompt action, the damage can be limited, and sites can be secured. Additionally, this incident highlights the importance of keeping software up to date and using secure plugins, which can help prevent similar attacks in the future.
The attack may have already compromised a large number of sites, and the hidden backdoor can be difficult to detect. If not properly cleaned, the affected sites may remain vulnerable to further attacks, potentially leading to data breaches, financial losses, or other malicious activities. Furthermore, the disputed entry point and unclear extent of the breach may make it challenging for site administrators to determine the best course of action to secure their sites.



