Adform says attackers tampered with its website tracking script and used it to steal cryptocurrency from people visiting sites that loaded the code. The compromised 'trackpoint-async.js' script served from s2.adform.net monitored visitors' clipboards and web pages for Bitcoin, Ethereum, and TRON wallet addresses, then replaced them with attacker-controlled addresses; researchers also saw related Adform-hosted scripts sending victim IP and page data to an attacker server. Adform says the malicious code affected visitors on July 27, 2026 and has been removed.
Why it matters: This is a supply-chain attack: people could be exposed just by visiting a legitimate website that used Adform, and site owners may not have realized they were serving malicious code. Organizations using Adform should review logs and any third-party script integrity controls, while users who visited affected sites should follow Adform's advice and clear browser data.
info@thehackernews.com (The Hacker News)
2026.08.01
99% relevant
This is the same underlying event: attackers tampered with Adform’s script so websites loading it served code that swapped cryptocurrency wallet addresses, adding another report on the scope and mechanism of the compromise.
Bill Toulas
2026.07.31
100% relevant
This article establishes a distinct new incident: a malicious modification of Adform-hosted JavaScript that propagated crypto-stealing behavior to downstream websites using the company's advertising and tracking platform.
← Back to all stories