Online Ad Firm Adform’s Script Compromised to Steal Cryptocurrency, Thousands of Websites Affected
In a disturbing discovery, online advertising firm Adform has suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to thousands of websites using its ad platform. The malicious activity, which has been ongoing for the past week, allowed attackers to hijack clipboard content and redirect cryptocurrency payments to attacker-controlled addresses.
Adform, one of Europe’s largest adtech firms, provides a full-stack platform that includes Demand-Side Platform (DSP), Supply-Side Platform (SSP), ad servers, and management tools. The company’s JavaScript tracking script, called “trackpoint-async.js,” was compromised with a trojanized code that continuously monitors the clipboard of users visiting websites that embed it. If the script detected Bitcoin, Ethereum, or TRON wallet addresses, it replaced them with an attacker-controlled address to redirect cryptocurrency payments.
Security researcher Kevin Beaumont discovered the malicious activity and noted that the trojanized JavaScript was embedded in every website using Adform’s advertising platform. “This allows end-user devices of downstream websites to be compromised with crypto-stealing malware,” Beaumont explained. “Meaning if you visit example.com and they use Adform, example.com will compromise your device.”
The malicious code was not flagged as malicious by any of the available antivirus engines, making it difficult to detect. However, Beaumont observed that other malicious Adform-hosted scripts were communicating with an attacker-controlled server at 84.32.102[.]230:7744, sending the victim’s IP address, referring website, and URL path.
Adform quickly removed the malicious code from its tracking script after being notified by Beaumont on July 27. The company confirmed that it had detected suspicious activity and took measures to protect website visitors, clients, and the Adform platform. “To our knowledge, the code was not designed to install software on a user’s device or establish persistence,” Adform stated. “It operated only while an affected webpage was open.”
Individuals who visited websites that embedded the compromised Adform technology between July 26 and 27 are impacted and recommended to clear browser cookies to eliminate the malicious code. Adform has informed affected clients through dedicated communications and provided them with relevant information and recommended actions.
This incident highlights the importance of supply-chain security in preventing attacks on online platforms. As Beaumont noted, “The malicious activity delivered through Adform has been ongoing for the past week without being detected.” This emphasizes the need for constant vigilance and regular testing to ensure that all layers of a platform are secure.
To avoid falling victim to such attacks, it is essential to test every layer before attackers do. Security teams should regularly conduct breach and attack simulation tests to strengthen their SIEM and EDR rules, ensuring that threats are detected and prevented from slipping through detection.
Source: Bleeping Computer — 2026-07-31