UpdraftPlus WordPress Plugin Exploitation Targeting CDN API Credentials

Detects attempts to create rogue WordPress administrator accounts using indicators associated with the OptinMonster/TrustPulse supply chain attack. The rule specifically looks for POST requests to WordPress user creation endpoints (REST API, admin form, AJAX) containing campaign-specific identifiers like 'developer_api1', 'customer1usx', or patterns like 'dev_xxxxxx' in the response body or request URL. This covers the known vectors of the attack, aiming to identify the unauthorized creation of administrative users.