Ad Tag Compromise Turns Trusted Sites Into Stealers
A vendor-hosted tag can become the malware path for every visitor, so the real blast radius is the browsers of the sites that embed it, not just the ad network’s own infrastructure. In this case, Adform’s trackpoint-async.js was used to swap crypto-wallet addresses from the clipboard and send beacon traffic, which turns a normal ad embed into a covert theft channel.
The compromised script was tied to roughly 14,000 downstream sites. The payload was reportedly clean on VirusTotal, and the malicious code was seen serving from Adform-hosted content with beaconing to 84.32.102.230.
If you trust third-party JavaScript because it comes from a reputable vendor domain, this is the failure mode: the tag can be the thing that compromises your users even when your own site is untouched.
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker.
Adform compromised to serve crypto stealer via supply chain attack
Adform compromised to serve crypto stealer via supply chain attack Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category.