hacker-news · Crawled Aug 1, 2026
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
3 IoCs
Read original article ↗
AI Summary
Attackers compromised a JavaScript file, trackpoint-async.js, served by advertising company Adform, using it to conduct a supply chain attack that modified cryptocurrency wallet addresses in real time on affected websites. The malicious script, active at least on July 27, 2026, monitored and altered clipboard content and form inputs to replace legitimate Bitcoin, Ethereum, and Tron wallet addresses with attacker-controlled ones. The script also attempted to exfiltrate the hostname and path of visited pages to a remote server. The attack did not install persistent malware but operated entirely in-browser while the infected page was open, making detection and attribution more difficult.
AI-extracted · verify before operational use