Affected Systems
WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected. Impacts WordPress sites using these plugins during the compromise window.
Exploitation Status
Active supply-chain compromise confirmed. Malicious code was distributed through legitimate CDN infrastructure. Exploitation window and specific malicious payload details not specified in available data.
Business Impact
WordPress sites using affected plugins may have received compromised code through automatic updates or fresh installations. Potential for unauthorized access, data exfiltration, or further malware deployment depending on payload. Supply-chain attacks bypass traditional security controls as code is signed/distributed by legitimate vendor. Incident response required for all sites using these plugins.
Urgency
🔴 Immediate
Recommended Actions
- Immediately audit all WordPress installations for OptinMonster, TrustPulse, and PushEngage plugins and document installed versions
- Isolate affected WordPress sites and review web server logs, WordPress audit logs, and database activity for suspicious behavior during the compromise period
- Monitor Awesome Motive security advisories for clean plugin versions and apply updates immediately when available
- Scan affected sites with updated malware detection tools and review any unexpected file modifications or new admin accounts
- Implement CDN integrity monitoring and Subresource Integrity (SRI) checks for third-party plugin assets where feasible
