Adform Script Compromised in Supply-Chain Attack, Wallet Addresses Swapped
Hackers recently compromised the Adform advertising technology company's script to swap cryptocurrency wallet addresses across customer sites. On July 27, 2026, Adform detected the incident and immediately removed the malicious code.
The attackers modified a JavaScript file called trackpoint-async.js, which is used by Adform to run tracking codes on websites. The altered file contained two malicious blocks that appended hardcoded replacement strings for Bitcoin, Ethereum, and Tron address patterns.
The script rewrites addresses entered directly into form fields and intercepts copy, cut, paste, and input events. It also attempts an HTTP request to 84.32.102.230:7744 on page load with the hostname and path of the page the visitor is on. However, Adform claims it found no evidence that the code transmitted visitors' IP addresses or information about websites they visited.