Overview
- Adform removed an injected payload from its trackpoint-async.js tracking script after detecting suspicious activity on July 27 and has notified affected clients.
- Researchers found obfuscated code appended to the library that watched clipboard and input events and rewrote on-page wallet addresses to attacker-controlled values.
- The altered script attempted callbacks to an attacker server at 84.32.102.230:7744 and could send a visitor's IP, referring site, and page path, though Adform says no persistent software was installed.
- The compromise is a supply‑chain incident because a single third‑party Adform script could deliver the clipper to many unrelated downstream sites, increasing the potential blast radius.
- Key questions remain open: how the Adform delivery path was breached, how many visitors were exposed, whether any funds were stolen, and who operated the attacker infrastructure.