Back Optinmonster Security Incident: Tampered Script Served via OptinMonster and TrustPulse
We are responding to a security incident affecting OptinMonster and TrustPulse . An attacker gained access to a credential for our content delivery network (CDN) and used it to serve a tampered version of the JavaScript file that these products deliver to customer sites. For a limited window, sites that embed our script loaded this modified file directly from our CDN.
The malicious code only activated for logged-in WordPress administrators. When it ran on an affected site, it attempted to create a hidden administrator account and install a concealed backdoor plugin, then sent data to an attacker-controlled server. Ordinary site visitors were not targeted, but because the code can hand an attacker control of a site, any affected site should be treated as compromised.
Scope – what was and wasn’t reached:
Our application servers, our source code, and the systems that store your OptinMonster and TrustPulse account information are hosted separately and were not breached. We have no evidence that account data or personal details held by us were accessed. The compromise was limited to our marketing website server and, through a CDN API key stored on it, our CDN account. Importantly, this does not reduce the urgency for affected site owners: the file delivered to your site was tampered with, which is why the steps below still matter if you were in the exposure window.
Who needs to act now: If your site had OptinMonster or TrustPulse active and an administrator was logged in during the exposure window below, please treat your site as compromised and follow What to check and do right away. The most reliable checks happen on your server, not in the WordPress dashboard.
Based on our CDN provider’s logs, the unauthorized configuration with tampered files was in place for approximately a few hours on June 12, 2026 (UTC) . We are continuing to confirm the precise period during which affected content was served, and will update this notice as additional details are verified.
Only sites that loaded the affected script with an administrator logged in during this window could have been compromised.
The affected files were the standard embed scripts served from:
An attacker exploited a known vulnerability in a third-party WordPress plugin (UpdraftPlus) to gain access to the server hosting our marketing website . This server is entirely separate: different host, different infrastructure from the application servers that run OptinMonster and TrustPulse and that store customer data.
On the marketing server, the attacker located an API key for our CDN account. Using that key, they did not need to touch our application origin at all. They modified the files our CDN was serving, so the tampered script was delivered to sites embedding it for a limited period before we detected and reverted the change.
We have since remediated the marketing site, migrated it to a new server , and rotated all credentials , including the CDN API key.
On an affected site, when a logged-in administrator loaded a page, the code attempted to:
Because the backdoor hides from the WordPress admin screens, the dashboard alone will not tell you whether you’re affected. The reliable checks are on the server filesystem and via a server-side scan.
If you had OptinMonster or TrustPulse running on your website AND an administrator logged in to your WordPress site during the exposure window, do the following as soon as possible. If you’re unsure whether an admin was logged in, it’s safer to check.
If you find none of these indicators and had no administrator logged in during the window, your site is very likely unaffected and no action is required beyond standard hygiene (enable two-factor authentication, keeping software updated).
Our CDN configuration has been corrected and the tampered files removed, the affected credentials have been rotated, and the entry point on our marketing server has been remediated.
Remediating our systems does not clean a site that was already compromised. If your site was affected during the exposure window, the rogue administrator account and hidden backdoor plugin remain in place until you remove them using the steps above. We recommend acting promptly. We will update this page if additional relevant information emerges.
For site owners and security teams:
If you have questions, need help checking your site, or notice anything unusual, us at [email protected] . We’re prioritizing incident-related inquiries and will keep this page updated.
Protecting our customers is a priority for us. We understand this incident may be concerning, and we regret any disruption it has caused. The information above reflects our investigation to date, and we will update this page as additional details are confirmed.
— The OptinMonster / TrustPulse Team
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
