Adform and Websites using Adform's advertising platform: Online ad firm Adform’s script compromised to steal cryptocurrency

Adform and Websites using Adform's advertising platform: Online ad firm Adform’s script compromised to steal cryptocurrency

Adform Ad Platform Hit by Supply-Chain Attack, Delivering Crypto-Stealing Malware

Adform, one of Europe’s largest adtech firms, fell victim to a supply-chain attack that injected cryptocurrency-stealing scripts into websites using its advertising platform. Security researcher Kevin Beaumont discovered the malicious activity, which originated from trackpoint-async.js Adform’s JavaScript tracking script served from s2.adform.net embedded across client websites.

The trojanized script monitored users’ clipboards in real time, replacing copied Bitcoin, Ethereum, or TRON wallet addresses with attacker-controlled ones to divert cryptocurrency payments. Additionally, the malware could rewrite wallet addresses displayed on web pages, ensuring victims unknowingly sent funds to the threat actor. The script also exfiltrated victims’ IP addresses, referring websites, and URL paths to a command-and-control server at 84.32.102[.]230:7744.

Despite its malicious functionality, the script evaded detection by antivirus engines on VirusTotal, appearing clean at the time of analysis. Beaumont noted the attack had been active for at least a week before discovery, with the earliest confirmed sample dating to July 26.

Adform confirmed detecting the threat on July 27, removing the malicious code and implementing additional security measures. The company stated the script did not install persistent malware or execute beyond the affected webpage’s session. While services are now deemed safe, Adform advised users who visited impacted sites on July 27 to clear browser cookies. The firm has notified affected clients and continues its investigation.

Analysis of archived samples revealed the malicious payload was appended in obfuscated form to Adform’s legitimate tracking library, containing functions to hijack clipboard content and alter on-page wallet addresses. The incident underscores the risks of supply-chain attacks in digital advertising, where compromised third-party scripts can silently compromise end-user devices.

Source: https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/

Adform cybersecurity rating report: https://www.rankiteo.com/company/adform

"id": "ADF1785536671",
"linkid": "adform",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Websites using Adform’s '
                                              'advertising platform',
                        'industry': 'Digital advertising',
                        'location': 'Europe',
                        'name': 'Adform',
                        'size': 'Large',
                        'type': 'Adtech firm'}],
 'attack_vector': 'Malicious JavaScript injection via third-party tracking '
                  'script',
 'customer_advisories': 'Users who visited impacted sites on July 27, 2023, '
                        'should clear browser cookies.',
 'data_breach': {'data_exfiltration': 'Yes (to C2 server at '
                                      '84.32.102[.]230:7744)',
                 'personally_identifiable_information': 'No',
                 'sensitivity_of_data': 'Medium (non-PII but sensitive '
                                        'behavioral and financial data)',
                 'type_of_data_compromised': 'IP addresses, referring '
                                             'websites, URL paths, '
                                             'cryptocurrency wallet addresses'},
 'date_detected': '2023-07-27',
 'date_resolved': '2023-07-27',
 'description': 'Adform, one of Europe’s largest adtech firms, fell victim to '
                'a supply-chain attack that injected cryptocurrency-stealing '
                'scripts into websites using its advertising platform. The '
                'trojanized script monitored users’ clipboards in real time, '
                'replacing copied Bitcoin, Ethereum, or TRON wallet addresses '
                'with attacker-controlled ones to divert cryptocurrency '
                'payments. The script also exfiltrated victims’ IP addresses, '
                'referring websites, and URL paths to a command-and-control '
                'server.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to '
                                       'Adform and affected clients',
            'data_compromised': 'IP addresses, referring websites, URL paths, '
                                'cryptocurrency wallet addresses',
            'operational_impact': 'Temporary compromise of client websites via '
                                  'malicious script',
            'payment_information_risk': 'Cryptocurrency wallet addresses at '
                                        'risk of diversion',
            'systems_affected': 'Websites using Adform’s advertising platform'},
 'initial_access_broker': {'entry_point': 'Compromised JavaScript tracking '
                                          'script (trackpoint-async.js)'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The incident underscores the risks of supply-chain '
                    'attacks in digital advertising, where compromised '
                    'third-party scripts can silently compromise end-user '
                    'devices.',
 'motivation': 'Financial gain (cryptocurrency theft)',
 'post_incident_analysis': {'corrective_actions': 'Removed malicious code, '
                                                  'implemented additional '
                                                  'security measures, and '
                                                  'notified affected clients.',
                            'root_causes': 'Supply-chain compromise of '
                                           'Adform’s JavaScript tracking '
                                           'library'},
 'recommendations': 'Clear browser cookies if visiting affected sites on July '
                    '27, 2023. Enhance monitoring of third-party scripts and '
                    'implement stricter security controls for supply-chain '
                    'dependencies.',
 'references': [{'source': 'Kevin Beaumont (Security Researcher)'}],
 'response': {'communication_strategy': 'Notified affected clients and advised '
                                        'users to clear browser cookies',
              'containment_measures': 'Removed malicious code from the '
                                      'tracking script',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Implemented additional security '
                                      'measures'},
 'stakeholder_advisories': 'Adform has notified affected clients and advised '
                           'users to clear browser cookies.',
 'title': 'Adform Ad Platform Hit by Supply-Chain Attack, Delivering '
          'Crypto-Stealing Malware',
 'type': 'Supply-Chain Attack',
 'vulnerability_exploited': 'Compromised JavaScript library '
                            '(trackpoint-async.js)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.