Close Menu
NCIJ Network NCIJ Network
    What's Hot

    TIPS challenge the inflation story behind rising bond yields

    August 1, 2026

    How ‘On the Psychology of Military Incompetence’ Predicted Hegseth’s Iran Debacle

    August 1, 2026

    Peru’s ex-president leaves jail after 15-year jail term for corruption overturned

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • TIPS challenge the inflation story behind rising bond yields
    • How ‘On the Psychology of Military Incompetence’ Predicted Hegseth’s Iran Debacle
    • Peru’s ex-president leaves jail after 15-year jail term for corruption overturned
    • Labour’s Bev Craig elected new mayor of Greater Manchester
    • Silicon Valley loves young founders. Until it doesn’t.
    • Online ad firm Adform’s script compromised to steal cryptocurrency
    • US Is Banning Foreign Robots—Even Roombas
    • Mamdani discount grocery store meme shows unrelated photo, false claim about family
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Online ad firm Adform’s script compromised to steal cryptocurrency

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker.

    Adform is one of Europe’s largest adtech firms, providing a full-stack platform that includes Demand-Side Platform (DSP), Supply-Side Platform (SSP), ad servers, and management tools.

    Security researcher Kevin Beaumont discovered the malicious activity, saying that it stemmed from ‘trackpoint-async.js,’ Adform’s JavaScript tracking script served from ‘s2.adform.net’ and embedded in every website using the advertising platform.

    image

    According to the researcher, the trojanized JavaScript continuously monitors the clipboard of users visiting websites that embed trackpoint-async.js.

    If the script detected Bitcoin, Ethereum, or TRON wallet addresses, it replaced them with an attacker-controlled address to redirect cryptocurrency payments.

    Compromised Adform script replacing crypto addresses
    Compromised Adform script replacing crypto addresses
    source: BleepingComputer

    “This allows end-user devices of downstream websites to be compromised with crypto-stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device,” Beaumont explains.

    The researcher also observed other malicious Adform-hosted scripts communicating with an attacker-controlled server at 84.32.102[.]230:7744, sending the victim’s IP address, referring website, and URL path.

    Running the script through the VirusTotal scanning platform shows that it is not flagged as malicious by any of the available antivirus engines.

    VirusTotal scan of the script comes clean
    VirusTotal scan of the script gives clean result
    Source: doublepulsar.com

    Current status

    Beaumont notes that the malicious code was removed from Adform’s tracking script soon after his discovery.

    Adform confirmed its detected suspicious activity on July 27 and discovered a “cybersecurity threat.” The company said that it removed the malicious code and “took further measures to protect website visitors, our clients, and the Adform platform.”

    “To our knowledge, the code was not designed to install software on a user’s device or establish persistence. It operated only while an affected webpage was open,” Adform says.

    The company states that its services are now safe to use but its investigation continues.

    Individuals who visited websites that embedded the “affected Adform technology on 27 July 2026” are impacted and the recommendation is to clear browser cookies to eliminate the malicious code.

    “Adform has informed affected clients through dedicated communications and provided them with relevant information and recommended actions.” 

    Beaumont has shared a sample of the malicious script via Pastebin for security engineers to analyze.

    BleepingComputer’s analysis of a sample stored on Archive.org also confirmed that a self-executing payload had been injected into the Adform tracking library served from the company’s infrastructure.

    The malicious code was appended in obfuscated form at the end of the legitimate library and included a function that replaced any string matching a crypto wallet address format.

    Apart from hijacking clipboard content, the malware can also rewrite wallet addresses on web pages. This way, if a payment address is displayed, it would be the attacker’s.

    Beaumont says the malicious activity delivered through Adform has been ongoing for the past week without being detected. The oldest sample BleepingComputer could find was from from the Archive.org snapshot on July 26, taken at 23:29:03 GMT.

    BleepingComputer has contacted Adform to request a statement regarding Beaumont’s findings and will update the story if we receive a response.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Adforms Compromised cryptocurrency firm online script Steal
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

    Arch Linux disables AUR package adoption to stop malware flood

    Amgen says cloud data breach exposed patient health, proprietary info

    CareCloud Data Breach Impacts Over 350,000

    EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

    Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    TIPS challenge the inflation story behind rising bond yields

    August 1, 2026

    How ‘On the Psychology of Military Incompetence’ Predicted Hegseth’s Iran Debacle

    August 1, 2026

    Peru’s ex-president leaves jail after 15-year jail term for corruption overturned

    August 1, 2026

    Labour’s Bev Craig elected new mayor of Greater Manchester

    August 1, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    TIPS challenge the inflation story behind rising bond yields

    August 1, 2026

    How ‘On the Psychology of Military Incompetence’ Predicted Hegseth’s Iran Debacle

    August 1, 2026

    Peru’s ex-president leaves jail after 15-year jail term for corruption overturned

    August 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.