Awesome Motive WordPress Plugin Supply-Chain Compromise
Case score 93
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 93
- Main story score
- 93
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 1
- Incident Direct incident record for the PushEngage exposure, attacker behavior on downstream WordPress sites, and vendor containment actions. main
- Campaign Broader multi-plugin context showing the same malicious code pattern, shared delivery-path compromise, and exposure window across OptinMonster, TrustPulse, and PushEngage. context
Overview
Latest development Open development history Awesome Motive rotates CDN API key after WordPress CDN compromise Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.
-
PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign
On **June 12**, malicious JavaScript first appeared in **OptinMonster** and **TrustPulse** CDN-served files, then persisted longer in **PushEngage** delivery paths into **June 14**.
-
PushEngage scripts keep serving from some CDN servers into June 14
PushEngage's tampered script remains available from some client CDN servers into June 14, extending the exposure window for sites loading pushengage-web-sdk.js and pushengage-subscription.js from clientcdn.pushengage.com.
-
Sansec discloses malicious JavaScript across PushEngage, OptinMonster, and TrustPulse
Sansec discloses the wider campaign on June 13 after finding the same malicious code in JavaScript served for PushEngage, OptinMonster, and TrustPulse, and warns that any site that loaded the poisoned script should be treated as compromised.