logo

Attackers Hijack Popular WordPress Plugins to Deploy Backdoors

ID: bd3fd54f-7db6-5397-9edb-06bef394b1dc

STIX ID: report--bd3fd54f-7db6-5397-9edb-06bef394b1dc

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

...
...

Attackers hijacked JavaScript delivered by Awesome Motive for OptinMonster, TrustPulse and PushEngage, injecting dormant payloads that, when a site administrator loads a page, create new admin accounts, install a stealth backdoor plugin, and send credentials to a lookalike tidio.cc domain; OptinMonster alone runs on over a million sites, raising widespread supply-chain risk. Sansec observed the tampered scripts during short exposure windows (about half an hour for some plugins) and urged admins to check for unfamiliar admin accounts and traffic to tidio.cc.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.