LIVE · cybersecurity feed
Live wire
security

Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]

zeroday.news · 1d ago

Adform, a prominent European online advertising technology firm, experienced a supply-chain attack that injected cryptocurrency-stealing scripts into its tracking JavaScript, which is embedded on numerous websites utilizing its ad platform. The malicious script was designed to replace cryptocurrency wallet addresses copied to a user's clipboard with an attacker-controlled address, thereby redirecting potential payments.

Security researcher Kevin Beaumont identified the malicious activity, tracing it to Adform's `trackpoint-async.js` script, served from `s2.adform.net`. This script, present on every website using Adform's advertising platform, continuously monitored the clipboards of visitors for Bitcoin, Ethereum, or TRON wallet addresses. Upon detection, it would substitute these with an address belonging to the attacker.

The compromise meant that any end-user device visiting a website that integrated Adform's affected script could be impacted. The malicious code was appended in an obfuscated form at the end of the legitimate library and also possessed the capability to rewrite wallet addresses displayed directly on web pages, ensuring that any payment address shown would be the attacker's.

Beyond clipboard hijacking, other Adform-hosted scripts were observed communicating with an attacker-controlled server at `84.32.102[.]230:7744`, transmitting the victim's IP address, referring website, and URL path. Despite its malicious functionality, a scan of the script on VirusTotal did not flag it as harmful by any antivirus engines at the time of discovery.

Adform confirmed detecting "suspicious activity" and a "cybersecurity threat" on July 27, 2026. The company stated that it promptly removed the malicious code and implemented additional protective measures for website visitors, clients, and its platform. Adform clarified that, to its knowledge, the code was not designed to install software or establish persistence on a user's device, operating only while an affected webpage remained open.

The company has since declared its services safe for use, though its investigation is ongoing. Individuals who visited websites embedding the affected Adform technology on July 27, 2026, are considered impacted, and Adform recommends clearing browser cookies to eliminate any residual malicious code. Adform has also informed affected clients directly, providing relevant information and recommended actions.

Evidence suggests the malicious activity had been ongoing for approximately a week prior to its detection. The earliest known sample of the compromised script dates back to a snapshot from Archive.org on July 26, 2026, at 23:29:03 GMT. A sample of the malicious script has been shared publicly for security engineers to analyze.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.