Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites
A supply-chain attack targeting the WordPress plugins OptinMonster, TrustPulse, and PushEngage exposed more than 1.2 million websites to potential compromise after attackers injected malicious JavaScript into files distributed through official CDN infrastructure. The malware created hidden administrator accounts and installed stealthy backdoors on affected sites when visited by logged-in WordPress administrators. The campaign was discovered … The post Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites appeared first on CyberInsider.
A supply-chain attack targeting the OptinMonster plugin exposed over 1.2 million WordPress sites to potential compromise, leveraging a compromised CDN API key and injecting malicious JavaScript into files distributed through official CDN infrastructure.
Read the full article
This is a curated summary. The complete article is available at Cyber Insider.
