The Plugins Were Fine. Until Someone Swapped the Scripts.
PushEngage, OptinMonster, and TrustPulse are three widely-used WordPress plugins — tools that add functionality to WordPress sites, the platform that powers a large share of the internet — all run by one company, Awesome Motive. They handle push notifications, lead capture forms, and trust badges for millions of sites.
An attacker tampered with the JavaScript files these plugins load from external servers. The malicious code had one specific trigger: it only activated when a site administrator was logged in at the moment the script loaded. When that condition was met, the code quietly created a new admin account under the attacker's control and installed a backdoor (a concealed access point that allows re-entry even after the original intrusion is discovered).
Ordinary visitors never triggered it. Only the site's own admin did — unknowingly, just by doing their job.
Security firm Sansec uncovered the campaign on June 13, finding identical malicious code across all three plugins. PushEngage confirmed the incident the following day. As of June 15, Awesome Motive had not publicly addressed OptinMonster or TrustPulse.
Any site that ran these plugins during the window of compromise should be treated as fully compromised.
What to do:
- Open your WordPress admin panel and review every listed admin account. Remove any you did not create.
- Check your installed plugins for anything unfamiliar and delete it.
- Update all three plugins to their latest versions immediately.
- Ask your hosting provider to run a malware scan if you have any doubt.
Sources

