Adform Ad Script Hijacked to Swap Crypto Wallet Addresses in Browsers
Online advertising firm Adform had its JavaScript tracking library 'trackpoint-async.js' compromised in a supply chain attack discovered around July 27, 2026. Attackers injected an obfuscated payload into the legitimate script served from s2.adform.net, causing it to silently replace Bitcoin, Ethereum, and TRON wallet addresses both on users' clipboards and on web pages they viewed. The malicious script also transmitted victims' IP addresses, referrer URLs, and page paths to an external server at 84.32.102[.]230:7744. Because the script was delivered through Adform's infrastructure, numerous downstream websites unknowingly passed the compromised code to their visitors' browsers. Adform stated that no software was permanently installed and the attack's impact was confined to the period when an affected page remained open in the browser.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in