Adform ad script hacked to steal cryptocurrency

▼ Summary
– Adform suffered a supply-chain attack where its JavaScript tracking script, trackpoint-async.js, delivered crypto-stealing code to websites using its ad platform.
– The malicious script monitored visitors’ clipboards and replaced Bitcoin, Ethereum, or TRON wallet addresses with attacker-controlled ones, also rewriting wallet addresses on web pages.
– Security researcher Kevin Beaumont discovered the issue; the script communicated with an attacker server, sending IPs and page URLs, and evaded detection by all VirusTotal antivirus engines.
– Adform detected the threat on July 27, removed the malicious code, and stated it operated only while an affected webpage was open, with no software installation or persistence.
– The attack impacted visitors to affected sites on July 27, 2026, with the oldest malicious sample found from July 26; Adform advised clearing browser cookies and is continuing its investigation.
European adtech provider Adform has been hit by a supply-chain attack that injected cryptocurrency-stealing code into websites running its advertising platform. The malicious script intercepted clipboard data and swapped copied wallet addresses with ones owned by the attacker, redirecting digital currency payments.
Adform ranks among the largest advertising technology companies in Europe, offering a comprehensive stack that includes a Demand-Side Platform (DSP), Supply-Side Platform (SSP), ad servers, and management tools.
Security researcher Kevin Beaumont uncovered the breach, tracing it to trackpoint-async.js, a JavaScript tracking file hosted at `s2.adform.net` and loaded by every site using Adform’s services.
Beaumont found that the compromised script kept a constant watch on the clipboard of visitors to any webpage embedding that file. When it spotted a Bitcoin, Ethereum, or TRON wallet address, it instantly replaced it with a hijacker’s address, rerouting any intended transfer.
” This allows end-user devices of downstream websites to be compromised with crypto-stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device,” Beaumont explained.
Beyond clipboard hijacking, the researcher observed additional malicious scripts hosted on Adform’s infrastructure communicating with a remote server at `84.32.102[.]230:7744`. Those scripts relayed the victim’s IP address, the referring site, and the URL path back to the attacker.
A scan of the malicious script via VirusTotal shows zero detection across all antivirus engines, meaning the payload slipped past standard security tools.
Current status and response
Beaumont noted that the malicious code was purged from Adform’s tracking script shortly after he flagged the issue.
Adform confirmed it spotted suspicious activity on July 27 and identified what it called a “cybersecurity threat.” The company stated it removed the malicious code and “took further measures to protect website visitors, our clients, and the Adform platform.”
“To our knowledge, the code was not designed to install software on a user’s device or establish persistence. It operated only while an affected webpage was open,” Adform said in a statement.
The firm insists its services are now safe to use, though the investigation remains ongoing. Anyone who visited a site embedding the affected Adform technology on July 27, 2026 may have been exposed, and the company recommends clearing browser cookies to purge any lingering malicious code.
Adform says it has already reached out to impacted clients with detailed guidance and recommended next steps.
Beaumont has posted a sample of the malicious script on Pastebin for security teams to dissect.
BleepingComputer’s own review of a copy preserved on Archive.org confirmed that a self-executing payload had been appended to the legitimate Adform tracking library served from the company’s infrastructure. The obfuscated code sat at the end of the original file and contained a function designed to rewrite any string matching a crypto wallet format.
The malware does more than just tamper with clipboards. It can also alter wallet addresses displayed directly on web pages, meaning even a visible payment address could be swapped for the attacker’s without the user noticing.
Beaumont estimates the malicious activity had been running undetected for about a week. The earliest sample BleepingComputer located came from an Archive.org snapshot dated July 26 at 23:29:03 GMT.
BleepingComputer has reached out to Adform for comment on Beaumont’s findings and will update this story if a response arrives.
(Source: BleepingComputer)




