Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
By [email protected] (The Hacker News)
AI Summary
Attackers modified a JavaScript file served by ad-tech firm Adform on July 27, 2026, turning it into a browser-side clipboard hijacker that silently replaced Bitcoin, Ethereum, and other cryptocurrency wallet addresses on any site carrying the script. Adform detected, removed the malicious code, and notified affected clients and authorities the same day, but any visitor who copied a wallet address during that window may have sent funds to attacker-controlled addresses. This supply chain attack on a widely-distributed advertising script represents a high-impact clipper deployment with broad blast radius across Adform's customer base.
Relevance score: 85.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →