Online ad firm Adform’s script compromised to steal cryptocurrency

Online Advertising Firm Adform Hit by Supply-Chain Attack, Cryptocurrency Stealers Prey on Unaware Users

A sophisticated supply-chain attack has compromised online advertising firm Adform’s script, allowing hackers to steal cryptocurrency from unsuspecting users. The malicious code, embedded in Adform’s JavaScript tracking script, monitored clipboard activity and replaced legitimate wallet addresses with attacker-controlled ones, siphoning off digital funds.

Adform, one of Europe’s largest adtech firms, provides a comprehensive platform for online advertisers, including demand-side platforms (DSP), supply-side platforms (SSP), ad servers, and management tools. Security researcher Kevin Beaumont discovered the malicious activity, attributing it to Adform’s “trackpoint-async.js” JavaScript tracking script served from “s2.adform.net”. This script was embedded in every website using the advertising platform, putting millions of users at risk.

The compromised script continuously monitored clipboard activity, looking for Bitcoin, Ethereum, or TRON wallet addresses. Once detected, it replaced these legitimate addresses with attacker-controlled ones, redirecting cryptocurrency payments to the hacker’s address. According to Beaumont, this allowed end-user devices of downstream websites to be compromised with crypto-stealing malware.

The malicious code was not flagged as malicious by any antivirus engines, further highlighting its sophisticated nature. However, Beaumont notes that the malicious code was removed from Adform’s tracking script soon after his discovery. The company confirmed detecting suspicious activity on July 27 and took measures to protect website visitors, clients, and the platform.

While Adform has assured users that its services are now safe to use, individuals who visited websites embedding the affected Adform technology between July 26 and 27 may still be impacted. To eliminate the malicious code, it is recommended that users clear browser cookies. Affected clients have been informed by Adform through dedicated communications, along with relevant information and recommended actions.

The attack highlights the importance of vigilance in online security. With supply-chain attacks becoming increasingly common, it’s essential for organizations to test every layer of their systems before attackers do. By conducting regular breach and attack simulation tests, security teams can identify vulnerabilities and strengthen their defenses against emerging threats.

In light of this incident, users are advised to be cautious when interacting with websites that use Adform’s advertising platform. Clearing browser cookies regularly can help eliminate any malicious code embedded in these platforms. As the cybersecurity landscape continues to evolve, it’s crucial for organizations and individuals alike to stay informed and adapt their security strategies accordingly.


Source: Bleeping Computer — 2026-07-31