Back Heise.De WordPress Plugins: Supply Chain Attack Puts 1.2 Million Sites at Risk
IT security researchers are warning of an active supply chain attack on the WordPress plugins OptinMonster, TrustPulse, and possibly PushEngage. Attackers are exploiting vulnerabilities in them to install backdoors in vulnerable WordPress instances. 1.2 million websites are said to be at risk.
This is reported by the authors of Sansec in their analysis . They have uncovered a supply chain attack on the plugins OptinMonster, TrustPulse, and PushEngage from the manufacturer Awesome Motive. The attackers have injected malicious JavaScript into the legitimate files delivered by Awesome Motive. These files are then embedded in the customer websites. The malicious JavaScript waits for an admin to log in, then creates a backdoor admin access and installs a self-hiding backdoor as a plugin; for other accesses, it remains dormant. It sends the new credentials to a domain “tidio.cc,” which imitates the regular site “tidio.com”. The campaign has been running since Friday, June 12, 2026.
Since the attackers gain full control over successfully attacked instances, other regular visitor accounts can also be misused. Awesome Motive also distributes other popular WordPress plugins. Although Sansec has only discovered malware in three so far, users of the other plugins should remain vigilant and monitor their systems for indicators of compromise (IOC). The OptinMonster plugin alone has over one million installations, Sansec explains. However, WPForms with over six million installations, All-in-One SEO (three million installations), or MonsterInsights (around two million installations) could also potentially be targeted by the attackers.
According to Sansec, IT security researchers from Patchstack have built detections and, using them, discovered hundreds of attack attempts on 13 sites on Sunday and Monday in a short period. Those using plugins from Awesome Motive should check the IOCs mentioned in the analysis.
Awesome Motive has since also responded and writes that attackers managed to obtain credentials for the Content Delivery Network and thus gain access to it. They used this to inject a manipulated version of the JavaScript that delivers the products to customer websites. For a limited period, the script delivered the modified file directly from the CDN. Awesome Motive emphasizes that application servers, source code, and the systems storing OptinMonster and TrustPulse account information are hosted independently and were not compromised.
The compromise was therefore limited to the marketing website and, via a CDN API key stored within it, to the CDN account. The manipulated software was distributed for a few hours on June 12, 2026. Websites that loaded the script and where admins logged in during that time window were compromised. The provider then offers assistance on how affected parties can clean up their systems.
Security vulnerabilities in WordPress plugins repeatedly serve attackers as an entry point to hijack systems. In early May, for example, attacks on the WordPress plugin Breeze Cache were observed. However, supply chain attacks like the one that just occurred have been rare so far.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
