Executive Summary
In June 2026, a significant supply chain attack targeted users of OptinMonster, TrustPulse, and PushEngage WordPress plugins, potentially affecting over 1.2 million websites. The threat actor gained access to a CDN API key by exploiting a vulnerability in a third-party plugin (UpdraftPlus) on the vendor's marketing server. This allowed them to modify the JavaScript SDKs served from the CDN, injecting malicious code directly into the browser sessions of logged-in administrators.
The attack is technically significant because it bypasses traditional network-layer security by weaponizing the administrator's own session and valid nonces. Once executed in an admin's browser, the script silently creates a hidden administrator account and installs a self-hiding backdoor plugin. This grants the attacker full unauthenticated code execution and file system access while remaining invisible within the WordPress dashboard.
Sites that had these plugins active and an administrator logged in between June 12 and June 14, 2026, are at high risk. Immediate manual inspection of the server filesystem is required, as the malware actively hides its presence from the WordPress UI and standard plugin lists.
