WalkureARCH (@WalkureARCH)
Posted
0 replies · 0 reposts · 1 likes
Attackers compromised a JavaScript tracking file served by advertising technology company Adform from its own CDN, injecting malicious code that silently replaced cryptocurrency wallet addresses across an unknown number of downstream customer websites. The poisoned trackpoint-async.js file targeted Bitcoin, Ethereum, and Tron addresses through two mechanisms: intercepting clipboard copy events and directly rewriting values in form fields and text nodes. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Independent security researcher Kevin Beaumont disclosed the compromise, noting the script also sent page hostnames to an external server. Adform stated there was no evidence that visitor IP addresses were collected or that any funds were diverted, though the full scope remains under investigation. The company advised users to clear browser caches because altered files may remain cached after the fix. https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html