Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Facebook X (Twitter) Instagram
Wednesday, June 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Attackers Hijack Popular WordPress Plugins to Deploy Backdoors
News

Attackers Hijack Popular WordPress Plugins to Deploy Backdoors

Team-CWDBy Team-CWDJune 15, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Attackers have hijacked the code behind several popular WordPress plugins to plant hidden backdoors and rogue administrator accounts on as many as 1.2 million sites.

The supply-chain attack, detailed by Dutch malware research firm Sansec on June 13, tampered with JavaScript served for OptinMonster, TrustPulse and PushEngage, three plugins run by WordPress vendor Awesome Motive.

Rather than living on victim servers, the malicious code rode in through Awesome Motive’s own delivery network, so any site loading the scripts pulled the tampered files straight from the source.

The payload stays dormant until a logged-in administrator loads a page, leaving ordinary visitors untouched, for now.

Read more on WordPress backdoor plugins: New WordPress Malware Masquerades as Plugin

From Tampered Script to Rogue Admin

When an admin is detected, the script springs into action. It creates a fresh administrator account, installs a self-hiding backdoor plugin to keep its grip, then ships the new credentials to a lookalike of the legitimate chat service tidio.com.

OptinMonster alone runs on more than a million sites, with TrustPulse and PushEngage adding the rest. Because the attacker effectively owns each compromised site, Sansec warned that abuse of regular visitors is likely to follow.

The firm likened the campaign to the 2024 Polyfill attack, in which poisoning a single upstream file affected thousands of downstream sites.

How the attackers got in remains unclear: the firm said Awesome Motive’s own servers, its CDN account or, less likely, the BunnyNet network behind it could be the entry point.

A Short Exposure Window

The exposure windows look short. Sansec logged the tampered OptinMonster and TrustPulse code for about half an hour late on June 12 before it disappeared, a hint the vendor had noticed, though the PushEngage script was still serving malware on June 13.

Only the three plugins are confirmed compromised, yet Awesome Motive’s reach runs far wider, spanning tens of millions of sites through products such as:

  • WPForms, with more than six million installs

  • All in One SEO, on around three million

  • MonsterInsights, on roughly two million

None of those is a confirmed hit, but Sansec urged anyone running an Awesome Motive plugin to watch for unfamiliar admin accounts and traffic to tidio[.]cc, and to act fast if either shows up.

Infosecurity has reached out to Awesome Motive for comment. 



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article19 Packages Poisoned to Auto-Run Bun Credential Stealer
Next Article New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing
Team-CWD
  • Website

Related Posts

News

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026
News

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026
News

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Chronology of a Skype attack

February 5, 2026

AI-powered financial scams swamp social media

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.