Particle.news

Adform Tracking Script Compromised to Swap Cryptocurrency Wallets

Attackers monitored clipboards to rewrite Bitcoin, Ethereum, TRON addresses in users' browsers creating a clear risk of misdirected crypto payments.

Overview

  • Adform removed an injected payload from its trackpoint-async.js tracking script after detecting suspicious activity on July 27 and has notified affected clients.
  • Researchers found obfuscated code appended to the library that watched clipboard and input events and rewrote on-page wallet addresses to attacker-controlled values.
  • The altered script attempted callbacks to an attacker server at 84.32.102.230:7744 and could send a visitor's IP, referring site, and page path, though Adform says no persistent software was installed.
  • The compromise is a supply‑chain incident because a single third‑party Adform script could deliver the clipper to many unrelated downstream sites, increasing the potential blast radius.
  • Key questions remain open: how the Adform delivery path was breached, how many visitors were exposed, whether any funds were stolen, and who operated the attacker infrastructure.