Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
vendor-distribution-compromisecredential-stealer-activitypersistence-methoddata-exfiltration-method

Compromised Awesome Motive CDN Backdoored WordPress Sites via Popular Plugins

Updated 7d agoFirst seen Jun 13, 20266 sources

Attackers tampered with JavaScript served from Awesome Motive infrastructure for the widely used WordPress plugins OptinMonster, TrustPulse, and PushEngage, triggering a supply-chain compromise that Sansec said exposed more than 1.2 million sites. The malicious code activated only when a logged-in WordPress administrator visited an affected site, then stole authentication data, exfiltrated site details to the typosquatted domain tidio.cc, created rogue administrator accounts, and deployed a stealth plugin designed to hide from normal WordPress administrative views.

Researchers said the hidden plugin provided unauthenticated remote code execution through a web shell and an eval-style endpoint, effectively giving attackers arbitrary PHP execution on compromised servers. Sansec verified malicious code in OptinMonster and TrustPulse CDN files beginning June 12 and said those paths were later cleaned, while some PushEngage CDN edges continued serving infected code until June 14; the exact initial compromise point remains unknown, but the distribution path ran through Awesome Motive-operated domains via BunnyNet CDN. Defenders were urged to treat any affected site with an administrator logged in during the exposure window as fully compromised, remove rogue users, search for hidden plugin directories, and rotate all administrator credentials and secrets.

Share:
Compromised Awesome Motive CDN Backdoored WordPress Sites via Popular Plugins
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 15, 20269d ago

Awesome Motive remediates server and rotates compromised credentials

Awesome Motive said it remediated the compromised marketing server, migrated the marketing site, and rotated credentials after the supply-chain attack. The company also stated that production systems, source code, and customer account data were not breached.

OptinMonster WordPress plugin hacked in CDN supply-chain attack

OptinMonster links attack to UpdraftPlus exploit and stolen CDN API key

According to OptinMonster’s disclosure, the supply-chain attack began when an attacker exploited a vulnerability in the UpdraftPlus plugin on OptinMonster’s marketing website and stole a CDN API key. The attacker then used that key to alter JavaScript files served from the vendor CDN to downstream WordPress sites.

OptinMonster Supply Chain Attack - CDN Poisoning at Scale - TheCyberThrone
Jun 14, 202610d ago

PushEngage continues serving malicious code until June 14

Sansec reported that the PushEngage plugin continued delivering malicious code from some CDN edges until June 14, 2026, after the other affected plugin paths were removed. This extended the exposure window for downstream WordPress sites using the compromised asset.

Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage
Jun 13, 202611d ago

Sansec discloses active supply-chain attack affecting WordPress plugins

On June 13, 2026, Sansec reported an active supply-chain compromise impacting more than 1.2 million WordPress sites via Awesome Motive infrastructure serving OptinMonster, TrustPulse, and PushEngage assets. Sansec said OptinMonster and TrustPulse paths had been cleaned on some edges, but PushEngage was still serving infected code and warned exposed sites should be treated as fully compromised.

OptinMonster supply chain attack hits 1.2 million sites | Sansec
Jun 12, 202612d ago

Malicious code first appears in OptinMonster and TrustPulse CDN files

Sansec said the first verified malicious JavaScript was served on June 12, 2026 through Awesome Motive CDN-hosted files for the OptinMonster and TrustPulse WordPress plugins. The injected code targeted logged-in WordPress administrators, stole authentication data, created rogue admin accounts, and installed a hidden backdoor plugin.

Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngage
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

30 LINKEDOpen in app
Affected products
4 linked
WordpressUpdraftplusWordfenceElementor
Organizations
18 linked
Awesome MotiveSansecTidioLinkedinXPatchstackGoogleOptinmonsterBunny.netPushEngageTrustPulseUpdraftplusElementorCheckmarxWordfenceUltahostSecurity AffairsFishPig
Breaches
7 linked
AWESOMEMOTIVE-2026-06TRUSTPULSE-2026-06OPTINMONSTER-2026-06PUSHENGAGE-2026-06WORDPRESSWEBSITESUSINGPUSHENGAGE-2026-06WORDPRESSWEBSITESUSINGOPTINMONSTER-2026-06WORDPRESSWEBSITESUSINGTRUSTPULSE-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Compromised Awesome Motive CDN Backdoored WordPress Sites via Popular Plugins | Mallory