← Blog

OptinMonster CDN Hack: WordPress Supply-Chain Attack Hits 1.2M+ Sites

Share on X

On June 15, 2026 BleepingComputer and Sansec reported a supply-chain attack against Awesome Motive CDN bundles for OptinMonster and TrustPulse—WordPress plugins used on more than 1.2 million websites.

Attack chain

Attackers exploited a known flaw in the UpdraftPlus WordPress plugin, stole a CDN API key, and replaced api.min.js files served from Awesome Motive domains. Malicious scripts targeted logged-in WordPress administrators—stealing session tokens to create rogue admin accounts and deploy web shells.

What site owners should do

  1. Audit WordPress users for unknown administrator accounts created around June 12, 2026.
  2. Rotate all WordPress admin passwords and enable MFA.
  3. Review Sansec and Awesome Motive advisories for compromised CDN hostnames.

Canonical record: OptinMonster supply chain 2026 on BreachHistory.

Sources: BleepingComputer, Sansec