Adform, a prominent European online advertising technology firm, experienced a supply-chain attack that injected cryptocurrency-stealing scripts into its tracking JavaScript, which is embedded on numerous websites utilizing its ad platform. The malicious script was designed to replace cryptocurrency wallet addresses copied to a user's clipboard with an attacker-controlled address, thereby redirecting potential payments.
Security researcher Kevin Beaumont identified the malicious activity, tracing it to Adform's `trackpoint-async.js` script, served from `s2.adform.net`. This script, present on every website using Adform's advertising platform, continuously monitored the clipboards of visitors for Bitcoin, Ethereum, or TRON wallet addresses. Upon detection, it would substitute these with an address belonging to the attacker.
The compromise meant that any end-user device visiting a website that integrated Adform's affected script could be impacted. The malicious code was appended in an obfuscated form at the end of the legitimate library and also possessed the capability to rewrite wallet addresses displayed directly on web pages, ensuring that any payment address shown would be the attacker's.
Beyond clipboard hijacking, other Adform-hosted scripts were observed communicating with an attacker-controlled server at `84.32.102[.]230:7744`, transmitting the victim's IP address, referring website, and URL path. Despite its malicious functionality, a scan of the script on VirusTotal did not flag it as harmful by any antivirus engines at the time of discovery.
Adform confirmed detecting "suspicious activity" and a "cybersecurity threat" on July 27, 2026. The company stated that it promptly removed the malicious code and implemented additional protective measures for website visitors, clients, and its platform. Adform clarified that, to its knowledge, the code was not designed to install software or establish persistence on a user's device, operating only while an affected webpage remained open.
The company has since declared its services safe for use, though its investigation is ongoing. Individuals who visited websites embedding the affected Adform technology on July 27, 2026, are considered impacted, and Adform recommends clearing browser cookies to eliminate any residual malicious code. Adform has also informed affected clients directly, providing relevant information and recommended actions.
Evidence suggests the malicious activity had been ongoing for approximately a week prior to its detection. The earliest known sample of the compromised script dates back to a snapshot from Archive.org on July 26, 2026, at 23:29:03 GMT. A sample of the malicious script has been shared publicly for security engineers to analyze.






