PushEngage hit by cyberattack
Incident
Summary
Hide ▲
Show ▼
Awesome Motive's WordPress plugin delivery paths for OptinMonster, TrustPulse, and PushEngage were hit in a CDN supply-chain incident after attackers stole a CDN API key from a server compromised through UpdraftPlus. The tampered JavaScript could activate when a WordPress administrator loaded an affected page, creating a rogue admin account, installing a hidden backdoor, and sending captured data to tidio[.]cc. OptinMonster is used on at least 1.2 million websites, and the incident exposed sites that loaded the poisoned files to site takeover risk.
Cases
Related Happenings
PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign
Campaign
H score89
First: 15.06.2026 12:59
Last: 15.06.2026 12:59
Sources 1
How related:
Security firm Sansec disclosed the wider campaign on June 13, finding the same malicious code in JavaScript served for all three plugins.
About this happening:
A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...
PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign
CampaignHow related: Security firm Sansec disclosed the wider campaign on June 13, finding the same malicious code in JavaScript served for all three plugins.
About this happening: A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...
Latest development: 15.06.2026 20:37
Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.
Funnel Builder security patch release (version 3.15.0.3)
Security Patch Release
H score77
First: 16.05.2026 18:20
Last: 16.05.2026 18:20
Sources 1
About this happening:
FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...
Funnel Builder security patch release (version 3.15.0.3)
Security Patch ReleaseAbout this happening: FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
Vulnerability
H score72
First: 16.05.2026 18:20
Last: 16.05.2026 18:20
Sources 1
About this happening:
Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw
VulnerabilityAbout this happening: Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...
Funnel Builder 3.15.0.3 security update
Security Patch Release
H score74
First: 15.05.2026 22:30
Last: 15.05.2026 22:30
Sources 1
About this happening:
FunnelKit released Funnel Builder 3.15.0.3 to fix an actively exploited flaw affecting WordPress/WooCommerce checkout pages, closing a path that could inject malic...
Funnel Builder 3.15.0.3 security update
Security Patch ReleaseAbout this happening: FunnelKit released Funnel Builder 3.15.0.3 to fix an actively exploited flaw affecting WordPress/WooCommerce checkout pages, closing a path that could inject malic...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
Campaign
H score34
First: 11.03.2026 16:45
Last: 11.03.2026 16:45
Sources 1
About this happening:
A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
CampaignAbout this happening: A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
Timeline
-
15.06.2026 20:37 1 articles · 1mo ago
Awesome Motive remediates CDN compromise and rotates credentials
Mitigation Patch UpdateAwesome Motive remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key, after attackers exploited a known UpdraftPlus flaw to steal CDN account credentials from a server in its environment and modify JavaScript served from the company's CDN. The company says its application servers, source code, and systems storing OptinMonster and TrustPulse account information were hosted separately and were not breached.
Show sources
- OptinMonster WordPress plugin hacked in CDN supply-chain attack — www.bleepingcomputer.com — 15.06.2026 20:37
-
15.06.2026 12:59 1 articles · 1mo ago
tidio[.]cc is registered before the WordPress plugin compromise
Technical Analysis UpdateThe domain tidio[.]cc is registered on April 28, weeks before malicious JavaScript is served through PushEngage, OptinMonster, and TrustPulse, indicating preparation for a planned campaign that later uses the fake domain for data exfiltration from compromised WordPress sites.
Show sources
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites — thehackernews.com — 15.06.2026 12:59
-
15.06.2026 12:59 2 articles · 1mo ago
Poisoned plugin JavaScript creates attacker-controlled WordPress admin access
Exploitation ObservedOn June 12, malicious JavaScript delivered for PushEngage, OptinMonster, and TrustPulse can activate only when a logged-in WordPress administrator loads it, then use that session to create an attacker-controlled admin account and install a hidden web shell backdoor on the affected site.
Show sources
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites — thehackernews.com — 15.06.2026 12:59
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites — thehackernews.com — 15.06.2026 12:59
-
15.06.2026 12:59 2 articles · 1mo ago
PushEngage scripts keep serving from some CDN servers into June 14
Victim Impact UpdatePushEngage's tampered script remains available from some client CDN servers into June 14, extending the exposure window for sites loading pushengage-web-sdk.js and pushengage-subscription.js from clientcdn.pushengage.com.
Show sources
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites — thehackernews.com — 15.06.2026 12:59
- Attackers Hijack Popular WordPress Plugins to Deploy Backdoors — www.infosecurity-magazine.com — 15.06.2026 20:00
-
13.06.2026 03:00 1 articles · 1mo ago
Sansec discloses malicious JavaScript across PushEngage, OptinMonster, and TrustPulse
Initial DisclosureSansec discloses the wider campaign on June 13 after finding the same malicious code in JavaScript served for PushEngage, OptinMonster, and TrustPulse, and warns that any site that loaded the poisoned script should be treated as compromised.
Show sources
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites — thehackernews.com — 15.06.2026 12:59