惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
GbyAI
GbyAI
博客园 - 司徒正美
美团技术团队
Vercel News
Vercel News
IT之家
IT之家
U
Unit 42
Y
Y Combinator Blog
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
V
Visual Studio Blog
B
Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
博客园 - 叶小钗
A
About on SuperTechFans
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
B
Blog RSS Feed

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Attackers Hijack Popular WordPress Plugins to Deploy Back...
https://www.infosecurity-magazine.com/profile/alessandro-mascell · 2026-06-16 · via www.infosecurity-magazine.com

Attackers have hijacked the code behind several popular WordPress plugins to plant hidden backdoors and rogue administrator accounts on as many as 1.2 million sites.

The supply-chain attack, detailed by Dutch malware research firm Sansec on June 13, tampered with JavaScript served for OptinMonster, TrustPulse and PushEngage, three plugins run by WordPress vendor Awesome Motive.

Rather than living on victim servers, the malicious code rode in through Awesome Motive's own delivery network, so any site loading the scripts pulled the tampered files straight from the source.

The payload stays dormant until a logged-in administrator loads a page, leaving ordinary visitors untouched, for now.

Read more on WordPress backdoor plugins: New WordPress Malware Masquerades as Plugin

From Tampered Script to Rogue Admin

When an admin is detected, the script springs into action. It creates a fresh administrator account, installs a self-hiding backdoor plugin to keep its grip, then ships the new credentials to a lookalike of the legitimate chat service tidio.com.

OptinMonster alone runs on more than a million sites, with TrustPulse and PushEngage adding the rest. Because the attacker effectively owns each compromised site, Sansec warned that abuse of regular visitors is likely to follow.

The firm likened the campaign to the 2024 Polyfill attack, in which poisoning a single upstream file affected thousands of downstream sites.

How the attackers got in remains unclear: the firm said Awesome Motive's own servers, its CDN account or, less likely, the BunnyNet network behind it could be the entry point.

A Short Exposure Window

The exposure windows look short. Sansec logged the tampered OptinMonster and TrustPulse code for about half an hour late on June 12 before it disappeared, a hint the vendor had noticed, though the PushEngage script was still serving malware on June 13.

Only the three plugins are confirmed compromised, yet Awesome Motive's reach runs far wider, spanning tens of millions of sites through products such as:

  • WPForms, with more than six million installs

  • All in One SEO, on around three million

  • MonsterInsights, on roughly two million

None of those is a confirmed hit, but Sansec urged anyone running an Awesome Motive plugin to watch for unfamiliar admin accounts and traffic to tidio[.]cc, and to act fast if either shows up.

Infosecurity has reached out to Awesome Motive for comment.