Skip to content
Data Breach

Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network

Adform, a major advertising technology company serving roughly 14,000 businesses and holding nearly 30% of the demand-side platform market, has suffered a supply chain compromise that turned its trusted ad-serving infrastructure into a distribution channel for cryptocurrency-stealing malware. Securi...

· Aug 01, 2026 · 3 min read · 👁 0 views
Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network

Adform, a major advertising technology company serving roughly 14,000 businesses and holding nearly 30% of the demand-side platform market, has suffered a supply chain compromise that turned its trusted ad-serving infrastructure into a distribution channel for cryptocurrency-stealing malware.

Security researcher Kevin Beaumont uncovered the breach and revealed that attackers hijacked a widely used JavaScript file to silently infect visitors across thousands of downstream websites.

The compromised file, a tracking script hosted at Adform’s own domain, is embedded on countless client websites to monitor advertising performance.

Malicious payload file (Source: Kevin Beaumont)

Adform Advertising Platform Compromised

Because so many companies rely on this single script, attackers only needed to poison one file to potentially reach millions of end users. Anyone visiting a website that uses Adform’s tracking pixel could have unknowingly downloaded malicious code onto their device, making this a textbook supply chain attack.

Once loaded, the malicious script functions as a clipboard hijacker, a form of malware designed specifically to steal cryptocurrency. It continuously scans the victim’s clipboard every few seconds, checking for copied Bitcoin, Ethereum, or Tron wallet addresses. When it detects a legitimate wallet address, it silently swaps it for an attacker-controlled address.

Because cryptocurrency addresses are long strings of random characters, most users paste them without double-checking, meaning funds intended for a legitimate recipient can be redirected straight into a hacker’s wallet.

Disturbingly, the malware persists even if a victim notices the mismatch and recopies the address; it simply overwrites it again on the next polling cycle.

Beyond financial theft, the script also functions as a surveillance tool. It quietly logs the victim’s IP address, the originating website, and the specific URL path visited, then transmits this data back to an attacker-controlled server. This data collection reveals exactly how the supply chain compromise spreads and helps attackers map their reach across affected sites.

What makes this incident particularly alarming is how it evaded detection. Every file, URL, domain, and IP address associated with the attack returned clean results when checked against major antivirus and threat intelligence platforms.

The malicious code hid inside a script from a legitimate, trusted advertiser, allowing it to bypass standard security filters that typically flag suspicious third-party content.

As of this reporting, there is no public confirmation that Adform has notified affected customers or issued a formal disclosure. Kevin Beaumont has observed signs that the malicious code is being actively removed, suggesting either Adform or the attackers are aware the operation has been exposed.

For website operators using Adform’s services, immediate action is critical: audit third-party scripts, monitor outbound traffic to the identified attacker infrastructure, and rotate any exposed credentials.

TypeValueDescription
IP Address84.32.102[.]230Attacker-controlled beacon/C2 server (port 7744)
Domains2.adform[.]netCompromised Adform subdomain serving malicious script
URLhxxps://s2[.]adform.net/banners/scripts/st/trackpoint-async.jsMalicious tracking script delivering clipboard hijacker
File Hash (SHA-256)02ff86c7f9fe609a753ff15bda90baa3c3e0d4a2e559ec4fcf8a3de0954b7c55Malicious payload file (flags clean on VirusTotal)
Beacon URL Patternhxxp://84.32.102[.]230:7744/p?h=<domain>&u=<path>Data exfiltration request pattern (victim domain + URL path)

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you