OptinMonster supply chain attack hits 1.2 million sites

June 15, 2026, 5:15 p.m.

Description

An active supply-chain attack targeted over 1.2 million WordPress sites using OptinMonster, TrustPulse, and PushEngage plugins operated by Awesome Motive. Attackers injected malicious JavaScript into legitimate files served through Awesome Motive's CDN endpoints. The malware activates when a logged-in administrator accesses the site, creating backdoor admin accounts (developer_api1 and randomized dev_xxxxxx accounts) and installing a self-hiding PHP plugin. The backdoor provides unauthenticated code execution through a web shell and eval endpoint. Stolen credentials are exfiltrated to tidio.cc, a lookalike domain mimicking the legitimate tidio.com. The breach likely originated from compromised Awesome Motive servers or their BunnyNet CDN account. The campaign began in late April 2026 and remained active through mid-June, affecting OptinMonster (over 1 million installations), TrustPulse, and PushEngage users.

Date

  • Created: June 14, 2026, 2:55 p.m.
  • Published: June 14, 2026, 2:55 p.m.
  • Modified: June 15, 2026, 5:15 p.m.

Indicators

  • http://tidio.cc/cdn-cgi/*
  • http://tidio.cc/cdn-cgi/p
  • http://tidio.cc/cdn-cgi/
  • http://tidio.cc/cdn-cgi/b
  • http://a.trstplse.com/app/js/api.min.js
  • http://tidio.cc/cdn-cgi/pe-p
  • http://tidio.cc/cdn-cgi/l
  • http://tidio.cc/cdn-cgi/pe-l
  • http://a.opmnstr.com/app/js/api.min.js
  • http://tidio.cc/cdn-cgi/pe-b