Find notable cyber news and cases, enriched with sources, timelines, and signals.

Adform trackpoint-async.js clipboard-hijacking malware activity

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The trojanized Adform tracking script began monitoring visitors’ clipboards and swapping copied Bitcoin, Ethereum, and TRON wallet addresses with attacker-controlled ones, creating an active crypto-payment theft risk on websites that embedded the code. The malicious payload was delivered through trackpoint-async.js from s2.adform.net and operated only while affected pages were open. Related malicious scripts also sent victim IP addresses, referring websites, and URL paths to 84.32.102[.]230:7744. Adform said it removed the code after detecting suspicious activity on July 27, 2026.

Related Happenings

Adform hit by network compromise

Incident
H score24 First: 01.08.2026 00:09 Last: 01.08.2026 00:09 Sources 1

How related: Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker.

About this happening: Adform’s trackpoint-async.js tracking script was compromised in a supply-chain attack, causing downstream sites to deliver crypto-stealing code to visitors and red...

Openew[.]app cloaked malware download portal

Malware Activity
H score26 First: 29.05.2026 21:21 Last: 29.05.2026 21:21 Sources 1

About this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...

BadIIS malware deployment on compromised IIS servers in Thailand and Vietnam

Malware Activity
H score27 First: 30.01.2026 14:08 Last: 30.01.2026 14:08 Sources 1

About this happening: BadIIS is a malicious native IIS module used on compromised IIS servers to support SEO fraud and traffic manipulation. Cisco Talos says the activity is tied to...

Cosmali Loader delivery via Microsoft Activation Scripts typosquat

Malware Activity
H score26 First: 24.12.2025 19:44 Last: 24.12.2025 19:44 Sources 1

About this happening: A typosquatted Microsoft Activation Scripts (MAS) domain is distributing malicious PowerShell scripts that install Cosmali Loader on Windows systems, creating a pa...

Bitcoin Black and Codo AI VS Code extensions delivering infostealer

Malware Activity
H score31 First: 09.12.2025 00:30 Last: 09.12.2025 00:30 Sources 1

About this happening: The Bitcoin Black and Codo AI extensions on Microsoft's Visual Studio Code Marketplace are delivering an infostealer to developers' machines, creating immediat...

Timeline

  1. 01.08.2026 00:09 2 articles · 1h ago

    Adform trackpoint-async.js clipboard-hijacking malware activity

    Initial Disclosure

    An attacker injected malicious code into Adform's trackpoint-async.js tracking script and served it from s2.adform.net. The payload then hijacked clipboard content on embedded sites and rewrote cryptocurrency wallet addresses for payment theft.

    Show sources