As cited
Copy frozen at (site build).
threat intel
Adform compromised to serve crypto stealer via supply chain attack
Adform, an ad tech platform serving approximately 14,000 companies with a 30% market share in demand-side advertising, had its JavaScript tracking script compromised to deliver cryptocurrency-stealing malware to end users visiting client websites. The malicious code monitored clipboard activity and replaced cryptocurrency wallet addresses with attacker-controlled wallets while exfiltrating user IP addresses and referrer information. The compromise appears to have lasted at least a week and went undetected by security vendors, though the malicious payloads began disappearing as the incident was being documented.
Why it matters: Practitioners whose organizations use Adform or rely on websites that embed Adform scripts face direct risk of credential and cryptocurrency theft; immediate verification of user devices for infection and review of third-party script dependencies is warranted.
- Source published
- First seen by Cybersecurity Tracker