CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Adform compromised to serve crypto stealer via supply chain attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3556

As cited

Copy frozen at (site build).

threat intel

Adform compromised to serve crypto stealer via supply chain attack

Adform, an ad tech platform serving approximately 14,000 companies with a 30% market share in demand-side advertising, had its JavaScript tracking script compromised to deliver cryptocurrency-stealing malware to end users visiting client websites. The malicious code monitored clipboard activity and replaced cryptocurrency wallet addresses with attacker-controlled wallets while exfiltrating user IP addresses and referrer information. The compromise appears to have lasted at least a week and went undetected by security vendors, though the malicious payloads began disappearing as the incident was being documented.

Why it matters: Practitioners whose organizations use Adform or rely on websites that embed Adform scripts face direct risk of credential and cryptocurrency theft; immediate verification of user devices for infection and review of third-party script dependencies is warranted.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary