Adform suffered a supply-chain compromise after attackers trojanized the hosted JavaScript file trackpoint-async.js served from s2.adform.net/banners/scripts/st/trackpoint-async.js, causing websites that embedded the ad platform’s technology to deliver a cryptocurrency-stealing payload to visitors. The injected, obfuscated code monitored clipboard contents every few seconds for Bitcoin, Ethereum, and TRON wallet addresses, then replaced matching addresses with attacker-controlled wallets; reporting also indicates it could rewrite wallet addresses displayed directly on web pages to divert payments.
Security researcher Kevin Beaumont linked the malicious script to communications with attacker-controlled server 84.32.102[.]230:7744, which received victim IP addresses, referring websites, and URL path data. Adform said it detected suspicious activity on July 27, removed the malicious code, and notified affected customers, while external reporting suggests the compromise may have been active for roughly a week and that the appended payload initially evaded antivirus detection, with related file hashes appearing clean on VirusTotal.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
Adform stated that individuals who visited websites embedding the affected Adform technology on July 27, 2026 were impacted. It recommended those users clear browser cookies because the malicious code operated only while an affected webpage was open.
Adform said it reported the supply-chain compromise involving its trojanized tracking script to authorities after detecting and removing the malicious code. The company also notified affected clients and issued user guidance, but the report to authorities is the distinct new development.
Adform said it detected suspicious activity on July 27, discovered the cybersecurity threat, and removed the malicious code from its systems. The company also said it took additional protective measures and notified affected clients with recommended actions.
Reporting says an archived sample from July 26 showed the malicious payload appended in obfuscated form to the legitimate Adform tracking library. Analysis confirmed the injected code was being served from Adform infrastructure.
Technical analysis of the captured Adform sample showed two malicious code blocks appended to the legitimate library, with replacement strings obfuscated using a six-byte XOR key. Beyond clipboard hijacking, the malware also rewrote cryptocurrency wallet addresses entered directly into textarea, contenteditable, and input fields while preserving cursor position.
Kevin Beaumont documented that Adform-hosted scripts were beaconing to attacker-controlled server 84.32.102.230:7744 with victim IP address, referring website, and URL path data. During his write-up, he observed the malicious code appearing to disappear from Adform-served content.
Adform’s hosted JavaScript tracking library, trackpoint-async.js on s2.adform.net, was trojanized in a supply-chain compromise. The injected payload monitored clipboard contents for Bitcoin, Ethereum, and TRON wallet addresses and replaced them with attacker-controlled addresses; reporting says the activity may have been ongoing for about a week.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecysecurity.news
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcesite.adform.com
Open sourcedoublepulsar.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.