bleeping-computer · Crawled Jul 31, 2026
Online ad firm Adform’s script compromised to steal cryptocurrency
3 IoCs
Read original article ↗
AI Summary
Adform, a major online advertising platform, suffered a supply-chain attack where its JavaScript tracking script 'trackpoint-async.js' was compromised to deliver cryptocurrency-stealing malware. The malicious script, served from s2.adform.net, monitored users' clipboards and replaced copied cryptocurrency wallet addresses (Bitcoin, Ethereum, TRON) with attacker-controlled ones. It also had the capability to rewrite wallet addresses displayed on web pages. The malicious code communicated with a command-and-control server at 84.32.102[.]230 and was active for at least a week before being detected and removed on July 27, 2026.
AI-extracted · verify before operational use