Adform Ad Platform Compromised in Cryptocurrency-Stealing Supply-Chain Attack
Online advertising firm Adform was compromised in a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform.
The malicious code replaced wallet addresses copied to visitors' clipboards with ones controlled by an attacker, allowing them to redirect cryptocurrency payments. The attack affected users who visited websites embedding Adform's JavaScript tracking script, which is served from 's2.adform.net'.
Security researcher Kevin Beaumont discovered the malicious activity and reported that it had been ongoing for at least a week without being detected.