Online advertising platform Adform has confirmed that one of its shared tracking scripts was compromised and briefly turned into a crypto-stealing tool, swapping cryptocurrency wallet addresses for visitors across downstream customer sites.[1][2][5] The malicious modification targeted Adform’s widely deployed trackpoint-async.js file and turned a routine analytics include into a supply chain attack on every site that embedded the tag.[1][2][3][7]
According to independent analyses, the injected payload monitored the clipboard of visitors and looked for Bitcoin, Ethereum, and TRON wallet strings, replacing them with attacker-controlled addresses so that any subsequent payment would be silently redirected.[2][7] Researchers also found that the altered script could swap addresses entered directly into web form fields, meaning users did not need to rely on copy‑paste for the attack to succeed.[1] Adform has stated that, to its knowledge, the malicious code did not install software or establish persistence on user devices and operated only while an affected page was open.[1][2]
Adform says it detected suspicious activity on July 27, 2026, removed the malicious blocks from the tracking library, informed affected clients, and reported the incident to authorities.[1][2][5] The company’s public notice frames the impact window as a single day, but security researcher Kevin Beaumont reports seeing crypto-stealing activity delivered via Adform’s infrastructure over roughly the preceding week, suggesting the threat may have been active longer than the vendor initially indicated.[1][2][10] Other reporting estimates that the compromised tag was embedded on around 14,000 downstream sites, highlighting how a single vendor-hosted script can magnify risk across a large web ecosystem.[3][7]
Although Adform has cleaned the script on its servers, cached copies may still reside in users’ browsers and on intermediary infrastructure, so the company is urging anyone who visited sites using the affected technology on July 27 to clear their browser cache and cookies and carefully verify any wallet address before sending funds.[1][2] A captured sample of the trojanized file reviewed by multiple researchers shows two malicious blocks appended to the legitimate library, including a component that beacons to an external server and can send visitor IP addresses and page metadata.[1][2][7] Adform, however, says its investigation has found no evidence that the injected code transmitted IP addresses or information about the websites people visited, underscoring that some details of the data exposure remain contested while forensic work continues.[1]
The incident comes after a previously disclosed flaw in Adform’s infrastructure, tracked as CVE-2025-50891, which affected the server-side backend for Adform Site Tracking and allowed HTML injection or arbitrary code execution via cookie hijacking with a CVSS v3 base score of 7.2, rated high severity.[9][11] That 2025 vulnerability was remediated on the provider side and did not require customer updates, but it illustrates how weaknesses in centralized tracking services can cascade into broad exposure for sites that rely on them.[9][11] No dedicated CVE has yet been issued for the July 2026 JavaScript compromise, which is being treated instead as a supply chain incident involving a trusted client-side tag.[1][2]
For organizations that embed Adform tags, the immediate priority is to identify pages that loaded the compromised script, review recent cryptocurrency transactions for evidence of address substitution, and notify users whose payments could have been diverted.[1][2] Adform recommends continuing to monitor for unusual activity while its investigation proceeds and has shared guidance with affected clients on mitigation steps.[1][2] More broadly, the episode reinforces the need for strict governance over third‑party JavaScript, including limiting the number of external tags, enforcing content security policies, and using subresource integrity and tagging inventories so that a single poisoned script cannot silently turn thousands of otherwise trusted sites into opportunistic theft channels.
References
- Hackers Poison Adform Script to Swap Crypto Wallet …
- Online ad firm Adform’s script compromised to steal …
- Ad Tag Compromise Turns Trusted Sites Into Stealers
- Hackers Poison Adform Script to Swap Crypto Wallet …
- Деньги ушли хакерам. Рекламная сеть Adform тайно воровала криптовалюту за секунду до перевода
- CVE-2025-50891 | INCIBE-CERT
- Kevin Beaumont’s Post
- CVE-2025-50891 – OpenCVE
