
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been breached in a supply-chain attack affecting Awesome Motive’s content delivery network (CDN).
Among the three products, the OptinMonster lead-generation and conversion optimization platform is the most widely used, powering at least 1.2 million websites.
E-commerce security firm Sansec identified the attack over the weekend and discovered that malicious scripts were delivered to unsuspecting OptinMonster and TrustPulse users on Friday between 22:17 UTC and 22:42 UTC.
PushEngage continued distributing harmful JavaScript code until 19:02 UTC on Saturday.
The malware activated only when a WordPress administrator accessed a page on an infected site, collecting authentication tokens and nonces, which were then used to generate a rogue administrator account.
The attackers subsequently installed a self-concealing backdoor plugin and set up a communication channel with a domain impersonating Tidio to transmit any newly captured data.
The plugin also offered full remote access capabilities, including a web shell (“WPM File Manager & Shell”) and arbitrary PHP code execution, granting attackers complete control over compromised websites.
“The operator rotates the plugin's disguise while keeping the logic byte-identical across renames,” Sansec states.
“We have observed it shipping as ‘Content Delivery Helper’ (content-delivery-helper, v2.7.1) and, currently, as ‘Database Optimizer’ (database-optimizer, v2.9.4).”
Awesome Motive released a security advisory earlier today regarding the incident, explaining that hackers gained entry to a server in its environment after exploiting a known vulnerability in the UpdraftPlus WordPress plugin.
This server hosted a marketing website and was not linked to the company’s production infrastructure or data systems; however, it contained credentials for the company’s CDN account, which the hackers stole.
Using the stolen CDN API key, the attackers altered JavaScript files distributed via Awesome Motive’s CDN, causing websites to silently load malicious code directly from the CDN.
The impacted files are:
a.omappapi.com/app/js/api.min.js – OptinMonster
a.opmnstr.com/app/js/api.min.js – OptinMonster
a.optnmstr.com/app/js/api.min.js – OptinMonster
a.trstplse.com/app/js/api.min.js – TrustPulse
Awesome Motive reports that the malicious scripts were served for a brief period on June 12 for OptinMonster and TrustPulse, though it does not confirm the impact on PushEngage.
“We have since remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key,” Awesome Motive stated.
The company also assured that its application servers, source code, and plugin hosting servers were not compromised.
“Our application servers, our source code, and the systems that store your OptinMonster and TrustPulse account information are hosted separately and were not breached,” stated the publisher.
“We have no evidence that account data or personal details held by us were accessed.”
Site owners who may have been affected are advised to:
Check for, and remove rogue admin accounts ‘developer_api1’ or ‘dev_xxxxxx’
Inspect the filesystem directly under wp-content/plugins for hidden backdoor plugins
Execute server-side malware scans
Rotate administrator passwords, API keys, database credentials, and WordPress security salts.
While the malicious content has been removed, the attacker continues to have access to compromised websites as long as the rogue administrator accounts and hidden backdoor plugins remain present.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
GitHub disables Microsoft repos pushing password-stealing malware
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
New IronWorm malware hits 36 packages in npm supply-chain attack
New Shai-Hulud malware wave compromises 600 npm packages
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages