HackMyIP
← Back to News
2026-08-01 The Hacker News

Adform Supply Chain Attack Swaps Crypto Wallet Addresses in Browser

Supply ChainMalwareThreat Intel

Advertising technology provider Adform disclosed a supply chain attack in which threat actors modified a shared JavaScript file, trackpoint-async.js, served from s2.adform[.]net, to rewrite cryptocurrency wallet addresses in users' browsers in real time. Detected on July 27, 2026, the poisoned script appended two malicious blocks to the legitimate library, using a six-byte XOR key to obfuscate replacement strings for Bitcoin, Ethereum, and Tron addresses. Because Adform's tracking code is deployed across thousands of customer sites, the compromise gave attackers a single point of entry into unrelated downstream properties without breaching each one individually. The incident was publicly disclosed by independent researcher Kevin Beaumont, who noted that the altered file and its associated infrastructure returned zero detections on VirusTotal at the time of the attack.

The malicious payload operated entirely in-browser and only while an affected page remained open, with no persistence mechanism or software installation. The first block monitored copy events and polled the clipboard every four seconds, swapping any matching wallet address with an attacker-controlled string while also beaconing to 84.32.102[.]230:7744 with the hostname and path of the visited page. The second block walked the document's text nodes, rewrote address values inside input, textarea, and contenteditable elements, and hooked the JavaScript value setter so even programmatic writes were intercepted. Security researchers can investigate the suspicious infrastructure using a WHOIS lookup on the C2 IP or a port scanner to check for additional services on port 7744.

Anyone who visited a site carrying the Adform script on July 27 and copied a crypto wallet address may have pasted a replacement address controlled by the attacker, potentially redirecting transfers at the point of payment. Adform has removed the malicious code and notified affected clients, but warns that the altered file may remain in browser caches even after the fix, advising users to clear their cache and verify every wallet address before sending funds. Users concerned about residual tracking or browser-level exposure can run a browser fingerprint test to audit what their browser reveals, or a privacy checkup to confirm their session is properly isolated. The full scope of the campaign remains unresolved, as Beaumont reported observing malicious Adform-served activity over the preceding week, suggesting the window of exposure may extend beyond the single date Adform has publicly acknowledged.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →