Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
ID: ff4c934f-c638-5643-bb2d-16d2a5f70f1d
STIX ID: report--ff4c934f-c638-5643-bb2d-16d2a5f70f1d
Feed Name: Security Affairs
Sansec reported an active supply-chain attack where attackers tampered with Awesome Motive CDN-hosted JavaScript for OptinMonster, TrustPulse, and PushEngage to target logged-in WordPress administrators: the script fingerprints sites, harvests tokens, creates backdoor admin accounts (developer_api1 and dev_xxxxxx), installs a stealth backdoor plugin that hides from the UI and exposes web-shell/eval endpoints, and exfiltrates data to a lookalike C2 domain (tidio.cc); the campaign was active in mid-June, delivered through multiple fallback network methods, and Sansec provided IoCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
