Connect with us

AI Security

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Published

on

A compromised JavaScript file distributed through advertising technology provider Adform was used by attackers to secretly replace cryptocurrency wallet addresses on websites, potentially redirecting payments to attacker-controlled wallets.

Adform confirmed that it detected the incident on July 27, 2026, removed the malicious code, informed affected customers, and reported the matter to relevant authorities.

The attack targeted a shared JavaScript resource used by websites integrated with Adform’s advertising and tracking services. Visitors who accessed affected pages and attempted cryptocurrency payments during the exposure window could have unknowingly sent Bitcoin, Ethereum, or Tron transactions to modified wallet addresses.

Malicious Script Modified Crypto Addresses in Browsers

The compromised file, identified as trackpoint-async.js and hosted on s2.adform[.]net, was altered to include malicious code capable of changing cryptocurrency wallet addresses directly inside a visitor’s browser.

Because the script was distributed through Adform’s infrastructure and loaded by multiple customer websites, attackers were able to impact unrelated sites without compromising each individual website separately.

This type of incident is known as a software supply chain attack, where attackers compromise a trusted third-party service to reach many downstream users.

Adform said the malicious code did not attempt to install malware or maintain long-term access on affected devices. Instead, it operated only while an infected webpage remained open.

Attack Worked Beyond Clipboard Replacement

Security researchers found that the malicious script could replace wallet addresses copied to the clipboard, but its capabilities extended further.

The code also monitored webpage content and modified wallet addresses entered directly into payment forms, including fields such as:

  • Text input boxes
  • Text areas
  • Editable browser elements

The script intercepted browser actions including copy, cut, paste, and input events. It also attempted to preserve cursor positions after changing values, helping the replacement activity remain less noticeable.

Researchers observed hardcoded replacement patterns targeting:

  • Bitcoin addresses
  • Ethereum addresses
  • Tron addresses

The destination addresses appeared to change between samples, making tracking more difficult.

Researchers Identify Malicious Code Components

Independent security researcher Kevin Beaumont reported the compromise and analyzed the altered script. Another researcher, Max Maass, published a captured copy of the malicious file from July 27.

Analysis showed that attackers appended two malicious sections to the legitimate JavaScript library.

The injected code used obfuscation techniques, including a six-byte XOR encryption key, to hide replacement strings and make analysis more difficult.

One component monitored clipboard activity, checking for cryptocurrency addresses and replacing them when detected. Another component scanned webpage content and manipulated address values displayed or entered by users.

Researchers also found that the script attempted to communicate with an external server at:

84.32.102[.]230:7744

The request included information related to the webpage being visited, such as the hostname and page path.

Data Collection Concerns Remain Under Investigation

Adform stated that it found no evidence that the malicious code transmitted visitor IP addresses or browsing information. However, the company acknowledged that technical analysis suggested such communication may have been possible.

The company has not confirmed whether data was successfully sent to attackers or whether any cryptocurrency funds were stolen.

Several important details remain unknown, including:

  • How attackers gained access to Adform’s script distribution system
  • How many websites served the modified JavaScript file
  • How many visitors were exposed
  • Whether attackers successfully redirected cryptocurrency payments

Adform has also not publicly identified the attackers or released indicators of compromise.

Adform Advises Users to Clear Cache and Verify Payments

Adform recommended that customers and users clear browser caches because the modified JavaScript file may remain stored locally even after the company removed the malicious version.

Users making cryptocurrency transactions should carefully verify wallet addresses before confirming payments, especially when copying addresses from websites or online payment forms.

Security experts also recommend avoiding blind trust in wallet addresses displayed by webpages and verifying transaction details through a separate trusted channel before sending funds.

Supply Chain Risks Continue to Grow

The incident demonstrates the risks created by third-party JavaScript dependencies and advertising technology platforms that operate across thousands of websites.

Adform reported significant global operations, with services supporting large-scale digital advertising activity. However, the company has not disclosed how many pages actually delivered the compromised script during the attack period.

As websites increasingly rely on external scripts for analytics, advertising, payments, and functionality, attackers continue to target these shared services as a way to reach large numbers of users through a single compromise.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO