Find notable cyber news and cases, enriched with sources, timelines, and signals.

Adform hit by network compromise

Incident
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

Adform’s trackpoint-async.js tracking script was compromised in a supply-chain attack, causing downstream sites to deliver crypto-stealing code to visitors and redirect wallet payments. The malicious script ran from s2.adform.net and targeted clipboard-copied wallet addresses. Adform said it detected suspicious activity on July 27 and removed the code, but the activity had already been active for about a week.

Related Happenings

Adform trackpoint-async.js clipboard-hijacking malware activity

Malware Activity
H score31 First: 01.08.2026 00:09 Last: 01.08.2026 00:09 Sources 1

How related: According to the researcher, the trojanized JavaScript continuously monitors the clipboard of users visiting websites that embed trackpoint-async.js.

About this happening: The trojanized Adform tracking script began monitoring visitors’ clipboards and swapping copied Bitcoin, Ethereum, and TRON wallet addresses with attacker-controlled o...

TamperedChef malvertising campaign distributing backdoor malware through trojanized PDFs

Campaign
H score37 First: 16.01.2026 14:05 Last: 16.01.2026 14:05 Sources 1

About this happening: The TamperedChef malvertising campaign used Google ads and more than 50 domains to push a fake AppSuite PDF Editor that later activated on August 21 to steal *...

Timeline

  1. 01.08.2026 00:09 1 articles · 1h ago

    Archived Adform tracking script contains a clipboard-hijacking payload

    Technical Analysis Update

    An Archive.org snapshot taken at 23:29:03 GMT on July 26 contained a self-executing payload appended to Adform's tracking library served from s2.adform.net. The injected code monitored clipboards, replaced Bitcoin, Ethereum, and TRON wallet addresses with attacker-controlled values, and sent the victim's IP address, referring website, and URL path to 84.32.102[.]230:7744.

    Show sources
  2. 01.08.2026 00:09 1 articles · 1h ago

    Adform removes malicious code from its tracking script

    Mitigation Patch Update

    Adform confirmed suspicious activity on July 27, identified a cybersecurity threat, removed the malicious code from its tracking script, and took further measures to protect website visitors, clients, and the Adform platform.

    Show sources
  3. 01.08.2026 00:09 1 articles · 1h ago

    Adform technology on downstream websites hijacks copied wallet addresses

    Victim Impact Update

    Individuals who visited websites that embedded the affected Adform technology on 27 July 2026 are impacted, and the recommended action is to clear browser cookies to eliminate the malicious code.

    Show sources
  4. 01.08.2026 00:09 2 articles · 1h ago

    Kevin Beaumont uncovers a compromise in Adform's trackpoint-async.js

    Initial Disclosure

    Kevin Beaumont identified malicious activity in trackpoint-async.js served from s2.adform.net and said the trojanized JavaScript continuously monitored clipboards, replaced Bitcoin, Ethereum, and TRON wallet addresses, and ran from an Adform-hosted tracking script embedded on websites using the advertising platform. A sample stored on Archive.org showed a self-executing payload injected into Adform's tracking library from the company's infrastructure.

    Show sources