Attackers compromised a JavaScript file distributed by advertising technology company Adform, transforming it into a browser based tool that automatically replaced cryptocurrency wallet addresses on websites using the affected script. The incident was detected by Adform on July 27, 2026, after which the company removed the malicious code, notified affected customers, and reported the matter to the relevant authorities. According to the company, anyone who visited a website using the compromised script on July 27 and copied a Bitcoin, Ethereum, or Tron wallet address may have unknowingly pasted a different address inserted by the malicious code. Adform has advised users to clear their browser cache because the altered JavaScript file may remain stored locally even after the issue was resolved. The company also urged users to carefully verify cryptocurrency wallet addresses before completing any transaction. Adform stated that the malicious code was not designed to install software or establish persistence and functioned only while the affected webpage remained open.
The compromised resource was identified as trackpoint async.js, served from s2.adform.net, a shared JavaScript library used across customer websites. According to Adform’s implementation guidance, the tracking script can be deployed on individual pages, selected sections, or across an entire website. Because numerous organizations relied on the same hosted resource, attackers were able to affect multiple downstream websites without directly breaching each customer environment, making the incident a supply chain compromise. Independent security researcher Kevin Beaumont disclosed the incident publicly and stated that malicious activity associated with Adform had been observed over a longer period than the company’s published timeline. While Adform identified July 27 as the affected date, Beaumont reported activity spanning the previous week, leaving the exact duration of exposure unresolved. Beaumont also noted that the malicious file, related domains, and associated IP addresses had no detections on VirusTotal at the time of discovery. Security researcher Max Maass separately published a captured copy of the malicious script on July 27 for further technical analysis.
Analysis of the captured JavaScript revealed two malicious code sections appended to the legitimate Adform library. The inserted payloads contained cryptocurrency wallet replacement routines protected with a six byte XOR obfuscation key. One component monitored copy events, attempted to read clipboard contents every four seconds, and automatically replaced Bitcoin, Ethereum, and Tron wallet addresses with attacker controlled alternatives. The same component also initiated an HTTP request to an external server located at IP address 84.32.102.230 on port 7744, transmitting the hostname and page path of the website being visited. The second malicious block traversed webpage text nodes and modified wallet addresses entered into input fields, text areas, and editable content while preserving cursor position to avoid alerting users. It also intercepted copy, cut, paste, and input events and modified values written programmatically into forms. Beaumont reported that even if users corrected a wallet address manually, the malicious script continued replacing it with attacker controlled values. The replacement addresses reportedly varied between transactions, making detection more difficult.
Adform stated that its investigation found no evidence confirming that visitors’ IP addresses or browsing information had been transmitted to attackers, although technical analysis indicated such transmission may have been possible. The company also confirmed that several important aspects of the incident remain under investigation, including how attackers compromised its deployment infrastructure, the total number of affected customer websites, the number of users exposed, and whether any cryptocurrency funds were successfully redirected. Adform has not published indicators of compromise or identified the threat actor responsible for the attack. According to the company’s 2025 annual report, Adform served approximately 1,800 customers, enabled around 1.5 billion advertisements each day, and operated across more than 180 countries. While those figures describe the scale of its advertising platform rather than the incident itself, security experts note that the actual impact will depend on how many websites loaded the compromised script and how many users interacted with cryptocurrency wallet addresses during the exposure period.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.