Supply Chain Attack on OptinMonster, TrustPulse, and PushEngage: Tampered CDN Scripts Auto-Creating Rogue Admins
A supply chain attack compromised the CDN-hosted JavaScript SDKs of OptinMonster, TrustPulse, and PushEngage, widely used WordPress marketing plugins. The injected client-side code silently created rogue admin accounts and backdoors by exploiting logged-in administrators' sessions. This incident highlights the risks of third-party CDN dependencies and requires immediate action from WordPress users to audit users, remove backdoors, and harden admin security.