Find notable cyber news and cases, enriched with sources, timelines, and signals.

PushEngage hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 93
3 unique sources, 3 articles

Summary

Hide ▲

Awesome Motive's WordPress plugin delivery paths for OptinMonster, TrustPulse, and PushEngage were hit in a CDN supply-chain incident after attackers stole a CDN API key from a server compromised through UpdraftPlus. The tampered JavaScript could activate when a WordPress administrator loaded an affected page, creating a rogue admin account, installing a hidden backdoor, and sending captured data to tidio[.]cc. OptinMonster is used on at least 1.2 million websites, and the incident exposed sites that loaded the poisoned files to site takeover risk.

Cases

Related Happenings

PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign

Campaign
H score89 First: 15.06.2026 12:59 Last: 15.06.2026 12:59 Sources 1

How related: Security firm Sansec disclosed the wider campaign on June 13, finding the same malicious code in JavaScript served for all three plugins.

About this happening: A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...

Latest development: 15.06.2026 20:37

Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.

Funnel Builder security patch release (version 3.15.0.3)

Security Patch Release
H score77 First: 16.05.2026 18:20 Last: 16.05.2026 18:20 Sources 1

About this happening: FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...

Funnel Builder plugin WordPress arbitrary JavaScript injection actively exploited security flaw

Vulnerability
H score72 First: 16.05.2026 18:20 Last: 16.05.2026 18:20 Sources 1

About this happening: Funnel Builder for WordPress is under active exploitation for arbitrary JavaScript injection into WooCommerce checkout pages, creating payment-skimming risk across...

Funnel Builder 3.15.0.3 security update

Security Patch Release
H score74 First: 15.05.2026 22:30 Last: 15.05.2026 22:30 Sources 1

About this happening: FunnelKit released Funnel Builder 3.15.0.3 to fix an actively exploited flaw affecting WordPress/WooCommerce checkout pages, closing a path that could inject malic...

Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims

Campaign
H score34 First: 11.03.2026 16:45 Last: 11.03.2026 16:45 Sources 1

About this happening: A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...

Timeline

  1. 15.06.2026 20:37 1 articles · 1mo ago

    Awesome Motive remediates CDN compromise and rotates credentials

    Mitigation Patch Update

    Awesome Motive remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key, after attackers exploited a known UpdraftPlus flaw to steal CDN account credentials from a server in its environment and modify JavaScript served from the company's CDN. The company says its application servers, source code, and systems storing OptinMonster and TrustPulse account information were hosted separately and were not breached.

    Show sources
  2. 15.06.2026 12:59 1 articles · 1mo ago

    tidio[.]cc is registered before the WordPress plugin compromise

    Technical Analysis Update

    The domain tidio[.]cc is registered on April 28, weeks before malicious JavaScript is served through PushEngage, OptinMonster, and TrustPulse, indicating preparation for a planned campaign that later uses the fake domain for data exfiltration from compromised WordPress sites.

    Show sources
  3. 15.06.2026 12:59 2 articles · 1mo ago

    Poisoned plugin JavaScript creates attacker-controlled WordPress admin access

    Exploitation Observed

    On June 12, malicious JavaScript delivered for PushEngage, OptinMonster, and TrustPulse can activate only when a logged-in WordPress administrator loads it, then use that session to create an attacker-controlled admin account and install a hidden web shell backdoor on the affected site.

    Show sources
  4. 15.06.2026 12:59 2 articles · 1mo ago

    PushEngage scripts keep serving from some CDN servers into June 14

    Victim Impact Update

    PushEngage's tampered script remains available from some client CDN servers into June 14, extending the exposure window for sites loading pushengage-web-sdk.js and pushengage-subscription.js from clientcdn.pushengage.com.

    Show sources
  5. 13.06.2026 03:00 1 articles · 1mo ago

    Sansec discloses malicious JavaScript across PushEngage, OptinMonster, and TrustPulse

    Initial Disclosure

    Sansec discloses the wider campaign on June 13 after finding the same malicious code in JavaScript served for PushEngage, OptinMonster, and TrustPulse, and warns that any site that loaded the poisoned script should be treated as compromised.

    Show sources