WordPress Plugin Supply-Chain Attack Hits Over 1.2 Million Sites
Security researchers at Sansec uncovered a sophisticated supply‑chain breach that injected malicious JavaScript into three widely used WordPress plugins – OptinMonster, TrustPulse and PushEngage – via the developer Awesome Motive’s CDN. The code remains dormant for regular visitors but activates when a logged‑in WordPress administrator accesses a site, automatically creating a hidden admin account and installing a back‑door plugin that provides file‑manager and command‑execution capabilities.
The intrusion potentially compromises the entire web presence of affected businesses, giving attackers full control over sites that use these marketing and push‑notification tools. Sansec estimates more than 1.2 million websites were exposed during the attack window. Providers responded quickly: infected files on OptinMonster and TrustPulse were removed within about 25 minutes, while PushEngage required cache clearing until June 14, 2026.
Experts advise organizations to verify whether administrators were logged in during the injection window, rotate passwords and API keys, and scan for indicators such as the developer_api1 account or hidden plugins named “content-delivery-helper” and “database-optimizer.”