Ad Tag Compromise Turns Trusted Sites Into Stealers
A vendor-hosted tag can become the malware path for every visitor, so the real blast radius is the browsers of the sites that embed it, not just the ad network’s own infrastructure. In this case, Adform’s trackpoint-async.js was used to swap crypto-wallet addresses from the clipboard and send beacon traffic, which turns a normal ad embed into a covert theft channel.
The compromised script was tied to roughly 14,000 downstream sites. The payload was reportedly clean on VirusTotal, and the malicious code was seen serving from Adform-hosted content with beaconing to 84.32.102.230.
If you trust third-party JavaScript because it comes from a reputable vendor domain, this is the failure mode: the tag can be the thing that compromises your users even when your own site is untouched.