On June 15, 2026 BleepingComputer and Sansec reported a supply-chain attack against Awesome Motive CDN bundles for OptinMonster and TrustPulse—WordPress plugins used on more than 1.2 million websites.
Attack chain
Attackers exploited a known flaw in the UpdraftPlus WordPress plugin, stole a CDN API key, and replaced api.min.js files served from Awesome Motive domains. Malicious scripts targeted logged-in WordPress administrators—stealing session tokens to create rogue admin accounts and deploy web shells.
What site owners should do
- Audit WordPress users for unknown administrator accounts created around June 12, 2026.
- Rotate all WordPress admin passwords and enable MFA.
- Review Sansec and Awesome Motive advisories for compromised CDN hostnames.
Canonical record: OptinMonster supply chain 2026 on BreachHistory.
Sources: BleepingComputer, Sansec