Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

August 1, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Adform customers and website visitors
Incident: Supply chain compromise of an Adform JavaScript library used to divert cryptocurrency payments.
Impact: Potential financial loss for users who transferred cryptocurrency to substituted wallet addresses.
Attacker: Unidentified threat actors
Analysis: Attackers compromised a shared JavaScript resource from Adform to execute a browser-side address-swapping attack. The script monitored clipboards and input fields to replace legitimate Bitcoin, Ethereum, and Tron addresses with attacker-controlled ones in real-time. This supply-chain vector allowed the threat actors to target users across numerous downstream customer sites simultaneously without needing to breach each one individually.
Recommendations: Clear browser caches to ensure outdated malicious scripts are removed; Manually verify cryptocurrency wallet addresses before finalizing any transfer; Implement Subresource Integrity (SRI) for third-party scripts to prevent unauthorized code execution
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *