In a supply chain attack, attackers install backdoors through the WordPress plugins OptinMonster, TrustPulse, and PushEngage.
Don't hold your breath, though – architect Brian Goetz warns devs it will likely still be preview in next LTS release ...