2026 Awesome Motive — OptinMonster CDN supply-chain attack (1.2M+ WordPress sites)
Data compromised
WordPress admin session tokens and site control for sites loading tampered CDN scripts—not end-user PII at publisher
Technical writeup
On June 12–15, 2026 Sansec and BleepingComputer reported that Awesome Motive’s CDN served malicious JavaScript to OptinMonster and TrustPulse users after attackers exploited a known UpdraftPlus vulnerability, stole a CDN API key, and replaced api.min.js bundles. The malware targeted logged-in WordPress administrators—harvesting auth tokens/nonces to create rogue admin accounts and deploy web shells—impacting sites using plugins with 1.2M+ OptinMonster installs. Awesome Motive said application servers storing customer account data were separate and not breached; credentials were rotated and the marketing site migrated.
Root cause
UpdraftPlus flaw led to stolen CDN API key; malicious JS served via OptinMonster/TrustPulse CDN