hacker-news · Crawled Aug 1, 2026

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

3 IoCs
Read original article ↗

AI Summary

Attackers compromised a JavaScript file, trackpoint-async.js, served by advertising company Adform, using it to conduct a supply chain attack that modified cryptocurrency wallet addresses in real time on affected websites. The malicious script, active at least on July 27, 2026, monitored and altered clipboard content and form inputs to replace legitimate Bitcoin, Ethereum, and Tron wallet addresses with attacker-controlled ones. The script also attempted to exfiltrate the hostname and path of visited pages to a remote server. The attack did not install persistent malware but operated entirely in-browser while the infected page was open, making detection and attribution more difficult.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Domain s2[.]adform[.]net Details →
IP 84[.]32[.]102[.]230 Details →
Filename trackpoint-async.js Details →