Stolen CDN Keys Turn Plugin Scripts Into Backdoors
A vendor script is only as trusted as the account behind it. Here, the break was not just poisoned plugin JavaScript. Awesome Motive says attackers first reached a marketing server through an unrelated UpdraftPlus flaw, stole CDN credentials, and used them to push malicious code that could create rogue admins and hide a backdoor plugin on any site that loaded it.
PushEngage has confirmed the exposure and published notice. Sansec tied the malicious JavaScript to OptinMonster, TrustPulse, and PushEngage, with OptinMonster and TrustPulse seeing a brief window on June 12 and PushEngage exposed longer into June 14. The three plugins reach more than 1.2 million sites, and the hidden plugin has shown up as Content Delivery Helper v2.7.1 and Database Optimizer v2.9.4.
The usual dashboard check can miss the real persistence layer, because the script only wakes up when a logged-in WordPress admin loads the page and then uses that session to plant a durable foothold. Removing the bad CDN file does not prove the site is clean if the attacker already created a new admin or left a self-hiding plugin behind.