Adform Supply Chain Attack Swipes Crypto Wallets from Affected Websites
An online advertising firm called Adform has been affected by a supply-chain attack. The attack was discovered on July 27, and it involves a script that injects cryptocurrency-stealing code into websites using Adform's ad platform.
The script, known as 'trackpoint-async.js,' is embedded in numerous websites and monitors user clipboards for Bitcoin, Ethereum, and TRON wallet addresses. If detected, the script replaces legitimate addresses with ones controlled by an attacker.
This method compromised end-user devices of downstream websites, meaning any site using Adform's platform could inadvertently infect visitors.