Threat reportSupply ChainTL-2026-0801

Awesome Motive WordPress Plugin Supply-Chain Attack (OptinMonster, TrustPulse, PushEngage) Delivering Self-Hiding Backdoor via Poisoned CDN JavaScript

criticalACTIVE

Awesome Motive WordPress Plugin Supply-Chain Attack (TL-2026-0801), also tracked as OptinMonster Supply Chain Attack, is a critical-severity supply-chain compromise scored CVSS 8.1, first published 2026-06-15. It has no confirmed attribution, affects Awesome Motive OptinMonster (WordPress plugin), references 1 CVE (CVE-2026-10795), maps to 22 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 23 indicators of compromise.

CVSS
8.1/10Critical
CVEs
1Referenced vulnerabilities
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-0801

Threat ID
TL-2026-0801
Also known as
OptinMonster Supply Chain Attack, Awesome Motive CDN Script Tampering, tidio.cc WordPress Backdoor Campaign
Severity
CRITICAL
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, e-commerce, media, small-business, marketing, hosting
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
23

How Awesome Motive WordPress Plugin Supply-Chain Attack works

Attackers injected malicious JavaScript into legitimate CDN-served scripts for Awesome Motive's OptinMonster, TrustPulse, and PushEngage WordPress plugins. The code activated only in logged-in administrator browsers, creating rogue admin accounts and installing a self-hiding backdoor plugin for unauthenticated remote command execution, then exfiltrating credentials to the lookalike C2 domain tidio[.]cc. Combined reach exceeds 1.2 million sites.

Between 2026-06-12 and 2026-06-14, security firm Sansec identified an active software supply-chain compromise affecting roughly 1.2 million WordPress sites that embed CDN-hosted JavaScript from Awesome Motive's OptinMonster (1M+ installs), TrustPulse, and PushEngage (9,000+ installs) plugins. Rather than compromising each victim site, the attackers tampered with the legitimate scripts served from Awesome Motive's own CDN endpoints (a.omappapi.com, a.opmnstr.com, a.optnmstr.com, a.trstplse.com, and clientcdn.pushengage.com), so the malicious code was delivered downstream to every embedding site.

The injected payload was heavily gated to evade analysis and limit noise. It exited immediately on navigator.webdriver, headless browsers, or zero-size windows, and only proceeded when it detected a WordPress administrator context (a wp-admin path, the admin bar, or the wordpress_logged_in_ cookie). It enforced a 24-hour throttle per browser via localStorage key _pe_ts to avoid repeated execution. Once gated through, the script fingerprinted the WordPress version, located the site root and admin paths, and harvested REST/AJAX nonces from multiple sources (wpApiSettings.nonce, admin-ajax.php?action=rest-nonce, and the user-new.php page) to authenticate privileged actions in the admin's session.

Using the stolen nonces, the payload created a backdoor administrator account through four fallback methods: the user-new.php form, admin-ajax.php, the REST endpoint wp/v2/users, and a hidden iframe form submission. It recognized 'user already exists' responses across roughly twenty languages to remain idempotent. A fixed account developer_api1 (customer1usx@gmail.com) and randomized dev_xxxxxx accounts were used. It then uploaded and activated a self-hiding PHP backdoor plugin disguised as 'Content Delivery Helper' (slug content-delivery-helper, v2.7.1) or 'Database Optimizer' (slug database-optimizer, v2.9.4). The plugin actively hid itself from the admin plugin list, the wp/v2/plugins REST endpoint, update checks, and activity logs. It exposed two unauthenticated entry points: a web shell reached via the ?developer_api1_fm parameter ('WPM File Manager & Shell' interface) that runs system commands from $_POST['cmd'], and a code-execution endpoint developer_api1_eval that eval()s base64-decoded attacker payloads. Harvested credentials were XOR-encrypted with the hardcoded key jX9kM2nP4qR6sT8v, base64-encoded, and exfiltrated to tidio[.]cc (a typosquat of the legitimate tidio.com) over several fallback transports, hitting paths /cdn-cgi/p, /cdn-cgi/b, /cdn-cgi/l for the OptinMonster/TrustPulse variant and /cdn-cgi/pe-p, /cdn-cgi/pe-b, /cdn-cgi/pe-l for the PushEngage variant.

The C2 domain tidio[.]cc resolved to 84.201.6.54 (Ultahost, AS214036) and was registered on 2026-04-28 with a TLS certificate issued the same day, indicating roughly six weeks of pre-staging. PushEngage attributed initial access to a known flaw in UpdraftPlus on its marketing server, referencing CVE-2026-10795 (an UpdraftPlus UpdraftCentral udrpc unauthenticated authentication bypass, CWE-347, CVSS 8.1) that allows forged RPC commands to run as the connected administrator and can lead to plugin upload and RCE. Sansec was unconvinced by that single explanation and assessed that Awesome Motive's own build/CDN infrastructure was the more likely tamper point. Exposure windows were narrow for OptinMonster/TrustPulse (~22:17-22:42 UTC on 2026-06-12) but lasted several hours for PushEngage, with injected code still observed on some CDN servers on 2026-06-13 and removed by 2026-06-14.

MITRE ATT&CK techniques used in TL-2026-0801

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1573 Encrypted Channel

Privilege Escalation

T1078 Valid Accounts

Persistence

T1098 Account Manipulation; T1136 Create Account

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise

persistence

T1505 Server Software Component

Discovery

T1518 Software Discovery

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities

Affected products and versions in Awesome Motive WordPress Plugin Supply-Chain Attack

  • Awesome Motive — OptinMonster (WordPress plugin)
    Vulnerable versions: CDN script a.omappapi.com/app/js/api.min.js served 2026-06-12 ~22:17-22:42 UTC; a.opmnstr.com/app/js/api.min.js; a.optnmstr.com/app/js/api.min.js
    Fixed in: clean script restored post-2026-06-12
  • Awesome Motive — TrustPulse (WordPress plugin)
    Vulnerable versions: CDN script a.trstplse.com/app/js/api.min.js served 2026-06-12 ~22:17-22:42 UTC
    Fixed in: clean script restored post-2026-06-12
  • Awesome Motive — PushEngage (WordPress plugin)
    Vulnerable versions: clientcdn.pushengage.com/sdks/pushengage-web-sdk.js served 2026-06-12 into 2026-06-13
    Fixed in: payload removed 2026-06-14
  • UpdraftPlus / TeamUpdraft — UpdraftPlus: WP Backup & Migration Plugin
    Vulnerable versions: <= 1.26.4
    Fixed in: 1.26.5

Remediation for Awesome Motive WordPress Plugin Supply-Chain Attack

Patches

  • Update UpdraftPlus to 1.26.5 or later (fixes CVE-2026-10795)
  • Apply Awesome Motive vendor fixes once the cleaned scripts are confirmed on all CDN edges

Immediate actions

  • Perform a server-side filesystem scan of wp-content/plugins for the folders content-delivery-helper and database-optimizer (trust disk over the dashboard, which the backdoor hides from)
  • Search the users table for and delete the account developer_api1 (customer1usx@gmail.com) and any dev_xxxxxx accounts
  • Block the C2 domain tidio[.]cc and IP 84.201.6.54 at the perimeter/DNS
  • Review web/access logs for 2026-06-12 through 2026-06-14 for outbound traffic to tidio.cc and requests containing developer_api1_fm or developer_api1_eval

Workarounds

  • Temporarily remove or block the affected Awesome Motive plugin scripts until vendor confirms CDN integrity
  • Rotate all administrator credentials, API keys, and wp-config.php authentication salts if any compromise indicator is present
  • Assume additional backdoors may remain after plugin removal and rebuild from known-good if unauthenticated RCE is confirmed

Longer-term hardening

  • Deploy Subresource Integrity (SRI) or self-host vendor scripts instead of loading third-party CDN JavaScript into admin contexts
  • Implement Content-Security-Policy restricting script sources and connect-src for the WordPress admin
  • Deploy server-side malware/file-integrity monitoring on wp-content
  • Restrict and monitor administrator account creation

CVEs associated with Awesome Motive WordPress Plugin Supply-Chain Attack

CVE-2026-10795

Weaknesses (CWE) in Awesome Motive WordPress Plugin Supply-Chain Attack

CWE-347, CWE-506, CWE-912, CWE-94

Timeline of Awesome Motive WordPress Plugin Supply-Chain Attack

  • TLS certificate for tidio.cc issued the same day as registration, enabling HTTPS credential exfiltration and indicating deliberate advance preparation of the C2 infrastructure.
  • C2 domain tidio.cc registered (typosquat of tidio.com), resolving to 84.201.6.54 (Ultahost, AS214036) — roughly six weeks of pre-staging before the attack.
  • CVE-2026-10795 (UpdraftPlus <= 1.26.4 unauthenticated authentication bypass via UpdraftCentral udrpc, CWE-347, CVSS 8.1) published; later cited by PushEngage as a possible initial-access vector on its marketing server.
  • PushEngage Web SDK script (clientcdn.pushengage.com) tampered for several hours the same day, a substantially longer exposure window than OptinMonster/TrustPulse.
  • Injected code last observed in the OptinMonster/TrustPulse CDN scripts at ~22:42 UTC, marking a narrow ~25-minute exposure window for those two plugins.
  • Tampered JavaScript first verified in the OptinMonster and TrustPulse CDN scripts at ~22:17 UTC, injecting the admin-gated backdoor payload into logged-in administrator browsers.
  • PushEngage CDN still observed serving the injected code (~19:02 UTC) with C2 domain tidio.cc still live after the OptinMonster/TrustPulse scripts had been cleaned.
  • Sansec publicly disclosed the supply-chain attack affecting roughly 1.2 million sites and assessed Awesome Motive's own build/CDN infrastructure as the most likely tamper point.
  • PushEngage payload removed from the CDN; PushEngage published customer notices attributing initial access to a known UpdraftPlus flaw on its marketing server.
  • The Hacker News reported the campaign affecting 1.2M+ Awesome Motive plugin sites; Sansec maintained that vendor build/CDN infrastructure—not the single UpdraftPlus theory—was the more likely tamper point.

Sources cited for Awesome Motive WordPress Plugin Supply-Chain Attack

Detection coverage for TL-2026-0801

As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0801 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats