Adform Suffers Supply-Chain Attack, Crypto-Stealing Script Injected into Ad Platform
A significant supply-chain attack targeted **Adform**, a major European adtech firm, leading to the injection of a cryptocurrency-stealing script into its widely used ad platform. The malicious code, delivered via **Adform**'s JavaScript tracking script, replaced users' copied crypto wallet addresses with attacker-controlled ones, potentially redirecting digital currency payments.
Online advertising giant **Adform** recently fell victim to a sophisticated supply-chain attack. This incident saw malicious JavaScript injected into its ad platform, subsequently distributing a cryptocurrency-stealing script to numerous websites utilizing **Adform**'s services.
### Malicious Script Hijacks Crypto Transactions
The attack specifically targeted users' clipboards, replacing legitimate Bitcoin, Ethereum, or TRON wallet addresses with those controlled by the attacker. This allowed for the potential redirection of cryptocurrency payments.
**Adform**, a full-stack adtech provider known for its Demand-Side Platform (DSP) and Supply-Side Platform (SSP), serves a vast network of websites across Europe.
### Discovery by a Security Researcher
Security researcher **Kevin Beaumont** was instrumental in uncovering the malicious activity. He identified the compromised component as 'trackpoint-async.js,' **Adform**'s JavaScript tracking script, which is served from 's2.adform.net' and embedded across all websites using the advertising platform.

According to **Beaumont**, the trojanized JavaScript continuously monitored the clipboards of users visiting sites that embedded *trackpoint-async.js*. Upon detecting a cryptocurrency wallet address, it would silently swap it with an attacker-controlled address.
"This allows end-user devices of downstream websites to be compromised with crypto-stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device," **Beaumont** explained.
He also observed other malicious **Adform**-hosted scripts communicating with an attacker-controlled server at 84.32.102[.]230:7744, transmitting victim IP addresses, referring websites, and URL paths.

Intriguingly, a scan of the script through **VirusTotal** revealed that it was not flagged as malicious by any of the available antivirus engines at the time of discovery, highlighting the stealthy nature of the attack.

### Swift Remediation and Ongoing Investigation
**Beaumont** confirmed that the malicious code was removed from **Adform**'s tracking script shortly after his discovery. **Adform** corroborated this, stating they detected suspicious activity on July 27 and promptly removed the offending code, implementing further protective measures.
**Adform** clarified that the code was not designed to install software or establish persistence on a user's device, operating only while an affected webpage was open. While the company asserts its services are now secure, the investigation is ongoing.
Individuals who visited websites embedding the affected **Adform** technology on July 27, 2026, are advised to clear their browser cookies to eliminate any residual malicious code. **Adform** has also informed affected clients directly, providing guidance and recommended actions.
**Beaumont** has made a sample of the malicious script available via **Pastebin** for security engineers to analyze. Further analysis by **BleepingComputer** of an **Archive.org** snapshot from July 26 confirmed the injection of an obfuscated, self-executing payload into the **Adform** tracking library. This payload included a function capable of replacing crypto wallet addresses not only in the clipboard but also directly on web pages.
The malicious activity is believed to have been ongoing for approximately a week before detection, with the earliest sample found dating back to July 26, 23:29:03 GMT.