FeedMalwareSupply-chain attack hits OptinMonster plugin used in 1.2 mil...
MalwareCyber Insider
9.5CRITICAL

Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites

📅 15 June 2026 at 12:00 UTC📰 Cyber InsiderView original source ↗
Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites

A supply-chain attack targeting the WordPress plugins OptinMonster, TrustPulse, and PushEngage exposed more than 1.2 million websites to potential compromise after attackers injected malicious JavaScript into files distributed through official CDN infrastructure. The malware created hidden administrator accounts and installed stealthy backdoors on affected sites when visited by logged-in WordPress administrators. The campaign was discovered … The post Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A supply-chain attack targeting the OptinMonster plugin exposed over 1.2 million WordPress sites to potential compromise, leveraging a compromised CDN API key and injecting malicious JavaScript into files distributed through official CDN infrastructure.

⚙️Technical Details
Affected Systems
OptinMonsterTrustPulsePushEngageUpdraftPlus
Attack Vectors
Compromised CDN API keyMalicious JavaScript injection
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Check for unauthorized administrator accounts and inspect the wp-content/plugins directory for hidden plugins
2Rotate all passwords, API keys, database credentials, and WordPress security keys
3Remove any detected backdoor plugins and assume attackers obtained full administrative access to the site
📦Affected Products
OptinMonsterTrustPulsePushEngage

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed