mimile
mimile.ai
Back to feed

Adform tracking script compromised to replace crypto wallet addresses

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Adform tracking script compromised to replace crypto wallet addresses

Europe’s adtech firm Adform suffered a supply-chain attack that injected malicious code into its tracking script, replacing Bitcoin, Ethereum, and TRON wallet addresses copied to users’ clipboards. Security researcher Kevin Beaumont discovered the trojanized script, which exfiltrated victim data to an attacker-controlled server. Adform removed the code on July 27, but users who visited affected websites that day remain at risk.

The Supply-Chain Compromise

Security researcher Kevin Beaumont discovered malicious code in Adform’s tracking script ‘trackpoint-async.js,’ hosted on s2.adform.net and embedded across all websites using the platform. The script monitored clipboards for Bitcoin, Ethereum, or TRON wallet addresses and quietly replaced them with addresses controlled by the attacker. Additional scripts communicated with a server at 84.32.102.230:7744, transmitting victim IP addresses, referring sites, and URL paths. At the time of discovery, no antivirus engines on VirusTotal flagged the script as malicious.

Adform’s Response

Adform confirmed suspicious activity on July 27 and identified a cybersecurity threat. The company removed the malicious code and stated it took further measures to protect clients and website visitors. According to Adform, the code did not install software or establish persistence, operating only while an affected webpage was open. Affected clients received dedicated communications with recommended actions, including clearing browser cookies to eliminate the injected payload.

Impact and Analysis

Individuals who visited websites embedding the affected Adform technology on July 27 may have had their cryptocurrency wallet addresses substituted during transactions. BleepingComputer’s analysis of an archived sample confirmed a self-executing payload appended to the legitimate library, containing a function that matched wallet address formats. Kevin Beaumont shared a sample of the malicious script on Pastebin for further scrutiny by security engineers.

What's Next

Adform’s investigation is ongoing, and it remains unclear how attackers initially compromised the script. Analysts caution that similar supply-chain attacks on advertising platforms could reoccur, and no arrests have been reported.

2 sources

Adform tracking script compromised to replace crypto wallet addresses