A critical vulnerability (CVE-2026-11976) involves the compromise of the official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`). Both the current release (10.2.2) and a rolled-back version (10.2.0) contain a malicious `class-system-check.php` file. Analysis of three observed variants on 2026-06-11 revealed identical AES-256-GCM encryption keys, confirming a single threat actor. The attacker retains write access to the S3 bucket and continues modifying payloads. This affects WordPress sites using MonsterInsights Pro via Amazon S3. The CVSS 10.0 score reflects the severity of remote code execution risks. Immediate actions include verifying file integrity, blocking access to the compromised S3 bucket, and monitoring for official security updates from the vendor.