CVE-2026-11976 (CVSS 10.0): The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) a (opens in a new tab)
Why readThe version MonsterInsights rolled back to is also poisoned and the attacker still holds write access to the bucket, so the obvious remediation makes things worse.
The S3 bucket serving MonsterInsights Pro updates was compromised and both the current 10.2.2 release and the 10.2.0 build the vendor reverted to carry a malicious class-system-check.php. Three payload variants observed on 11 June 2026 share one AES-256-GCM key, pointing to a single actor who was iterating on the implant during the day while retaining write access to the distribution bucket. Anyone running MonsterInsights Pro should check for the file directly rather than trusting a version number, since the trusted update channel is the delivery mechanism.