Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Between June 12-14 UTC, attackers compromised CDN-hosted JavaScript files delivered by BunnyNet for three widely deployed WordPress plugins from Awesome Motive (PushEngage, OptinMonster, and TrustPulse), collectively installed on approximately 1.2 million sites. Any WordPress administrator who loaded the tampered script during that window had their session privileges silently hijacked to create hidden admin accounts and install server-side web shells, leaving those sites under attacker control. Organizations running affected plugins must treat impacted sites as fully compromised and initiate server-side forensic investigation immediately, as the payload was engineered to evade detection through native WordPress tooling.

Author

Tech Jacks Solutions