bleeping-computer · Crawled Jul 31, 2026

Online ad firm Adform’s script compromised to steal cryptocurrency

3 IoCs
Read original article ↗

AI Summary

Adform, a major online advertising platform, suffered a supply-chain attack where its JavaScript tracking script 'trackpoint-async.js' was compromised to deliver cryptocurrency-stealing malware. The malicious script, served from s2.adform.net, monitored users' clipboards and replaced copied cryptocurrency wallet addresses (Bitcoin, Ethereum, TRON) with attacker-controlled ones. It also had the capability to rewrite wallet addresses displayed on web pages. The malicious code communicated with a command-and-control server at 84.32.102[.]230 and was active for at least a week before being detected and removed on July 27, 2026.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Domain s2[.]adform[.]net Details →
IP 84[.]32[.]102[.]230 Details →
Filename trackpoint-async.js Details →