Skip to content
Optinmonster Supply Chain Attack

Optinmonster Supply Chain Attack

sansec.io June 15, 2026

Malware adds admin accounts and hidden backdoor to sites using OptinMonster, TrustPulse or PushEngage plugins.

Sansec discovered an active supply-chain attack hitting over 1.2 million sites that use the popular OptinMonster, TrustPulse and PushEngage Wordpress plugins, all operated by Wordpress giant Awesome Motive.

Attackers added malicious JavaScript to the legitimate files served by Awesome Motive, which are embedded in their customer's sites.

The malware waits for a logged-in administrator, creates a backdoor admin account, and installs a self-hiding backdoor plugin. It then sends the new credentials to tidio.cc , a lookalike of the real tidio.com . The campaign is ongoing as of 13 June 2026.

The OptinMonster plugin alone has over a million active WordPress installations , and TrustPulse and PushEngage add many more. The payload only fires for logged-in admins, not for ordinary visitors. But as the threat actor effectively gains full control of individual sites, further abuse of regular visitors is to be expected.

Meanwhile, OptinMonster customers are complaining a service outage:

Awesome Motive runs one of the largest WordPress plugin portfolios in the world, used across tens of millions of sites. Other products include WPForms (over 6 million active installs), MonsterInsights (around 2 million) and All in One SEO (around 3 million). So far we have only confirmed a breach of OptinMonster, TrustPulse and PushEngage code, but anyone running an Awesome Motive plugin should stay alert, watch the indicators below, and patch as the company responds.

The malicious code did not live on any victim's own server but was injected via Awesome Motive's CDN endpoints. Any WordPress site loading one of these scripts pulled the tampered file directly from the source:

This resembles the Polyfill supply chain attack that Sansec discovered in 2024: tamper with a single upstream file, and the malware reaches thousands of downstream sites without ever touching them individually.

The payload is heavily gated and runs in stages:

The plugin that gets installed is built to disappear. It hides itself from the user list, the plugin list (both the admin screen and the REST /wp/v2/plugins endpoint), update checks, and the "recently active" list. On init , with no authentication required, it exposes two entry points:

The operator rotates the plugin's disguise while keeping the logic byte-identical across renames. We have observed it shipping as "Content Delivery Helper" ( content-delivery-helper , v2.7.1) and, currently, as "Database Optimizer" ( database-optimizer , v2.9.4). The plugin ZIP is generated fresh on each request: the script fetches tidio.cc/cdn-cgi/{pe-,}l?t=gen&u=developer_api1 , which returns a base64 blob that decodes through the same XOR key into the plugin id, slug and ZIP.

The malware was distributed via Awesome Motive-operated domains via the BunnyNet CDN. It is unknown which got hacked: Awesome Motive's own servers (likely), their CDN account (possible) or BunnyNet (unlikely). The fact that the malware for two of the three plugins quickly disappeared, suggest that they were aware of the breach. We have reached out to Awesome Motive but not received a response yet.

If you have one of these plugins installed and an admin logged in during the injection window, the damage is already done. Sorry.

If you find any indicators of compromise: rotate every admin password and secret, and assume the attacker has had unauthenticated code execution. Because the payload only ever ran for logged-in admins, server-side scanning is one of the most reliable ways to catch it.

You can run eComscan on your server to detect the backdoor plugin and rogue admin accounts, plus other malware, backdoors and vulnerabilities that may already be on your site.

Block all known Magento attacks, while you schedule the latest critical patch until a convenient moment. No more downtime and instability from rushed patching.

eComscan is the most thorough security scanner for Magento, Adobe Commerce, Shopware, WooCommerce, Sylius and many more.