A supply-chain attack on advertising technology company Adform exposed visitors to cryptocurrency theft through a compromised tracking script. The malicious code monitored copied wallet addresses and replaced them with addresses controlled by an attacker.

Compromised Adform script targets crypto payments

Security researcher Kevin Beaumont discovered the activity in trackpoint-async.js, an Adform JavaScript tracking file served from s2.adform.net.

The script is embedded on websites that use Adform’s advertising platform. Once loaded in a visitor’s browser, the altered code watched the clipboard for Bitcoin, Ethereum and TRON wallet addresses.

If it found a matching address, the script replaced it with an attacker-controlled wallet. As a result, users who pasted a crypto address to make a payment could unknowingly send funds to criminals instead.

Malware also rewrote addresses on webpages

The Adform supply-chain attack did not only target clipboard content. Analysis found that the injected payload could also change cryptocurrency wallet addresses displayed directly on an affected webpage.

This technique could cause a victim to see an attacker’s payment address rather than the intended recipient’s address. The malicious code was appended in obfuscated form to the end of the legitimate tracking library.

Researchers also found other Adform-hosted scripts communicating with an attacker-controlled server. Those scripts reportedly sent information including the visitor’s IP address, referring website and page path.

Adform removes malicious code

Adform said it identified suspicious activity on 27 July and discovered a cybersecurity threat. The company removed the malicious code and said it took additional measures to protect website visitors, clients and its platform.

According to Adform, the code was not designed to install software or maintain persistence on a device. Instead, it operated only while an affected webpage remained open.

The company said its services are now safe to use, although its investigation remains ongoing. Adform has also contacted affected clients with recommended actions.

Visitors urged to clear browser cookies

The malicious activity may have been active for roughly a week before it was detected. The oldest archived sample was reportedly captured on 26 July at 23:29 GMT.

People who visited sites using the affected Adform technology on 27 July 2026 should clear their browser cookies, according to the company. Users should also carefully verify any cryptocurrency payment address before sending funds.


0 responses to “Adform Supply-Chain Attack Hijacks Crypto Wallet Addresses”