OptinMonster WordPress plugin hacked in CDN supply-chain attack
ID: 09af8c5a-4c35-5163-b09e-cfe300ffce60
STIX ID: report--09af8c5a-4c35-5163-b09e-cfe300ffce60
Feed Name: Bleeping Computer
Awesome Motive's CDN was abused in a supply-chain attack after adversaries exploited a known UpdraftPlus vulnerability to steal CDN credentials and inject malicious JavaScript into OptinMonster, TrustPulse, and PushEngage distributions; the payload collected admin tokens, created rogue admin accounts, installed stealth backdoor plugins (including a web shell and arbitrary PHP execution), and exfiltrated data before the company remediated the marketing server and rotated credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
