A supply chain attack targeting digital advertising platform Adform temporarily transformed a widely deployed JavaScript library into a cryptocurrency wallet hijacking tool, potentially exposing visitors across numerous websites to unauthorized fund transfers.
The incident, detected by Adform on July 27, involved attackers modifying the company’s trackpoint-async.js script, which is distributed through Adform’s advertising infrastructure and embedded across customer websites. This Supply Chain attack did not target individual websites separately. Instead, the attackers compromised a shared resource capable of reaching multiple downstream sites simultaneously, demonstrating how a single vulnerable component can impact numerous organizations.
Adform removed the malicious code shortly after discovering the Supply Chain compromise, notified affected customers, and reported the incident to relevant authorities. The company has also urged users who visited websites carrying the affected script on July 27 to clear their browser cache because the altered JavaScript file may remain stored locally even after the original file was restored, helping reduce any lingering effects of the Supply Chain attack.
Malicious Script Replaced Cryptocurrency Wallet Addresses
The compromised script functioned entirely inside visitors’ browsers while affected webpages remained open.
According to the technical analysis, the malicious code monitored cryptocurrency wallet addresses associated with Bitcoin, Ethereum, and Tron. Whenever users copied or entered one of these addresses, the script attempted to replace it with an attacker-controlled wallet address before the transaction was completed.
The Supply Chain attack extended beyond clipboard manipulation.
Researchers found the malware also rewrote wallet addresses entered directly into input fields, text areas, and editable web content. Even users who manually retyped or recopied wallet addresses could still receive substituted addresses because the malicious code continuously monitored browser activity.
Independent cybersecurity researcher Kevin Beaumont, who publicly disclosed the compromise, noted that repeated attempts to copy the correct address continued to result in replacement while the malicious page remained active.
Supply Chain Attack Expanded Potential Reach
Unlike conventional website compromises that affect a single domain, this incident exploited the software supply chain.
Because Adform’s tracking library can be deployed across entire websites or multiple sections of customer properties, the Supply Chain compromise of the centrally hosted script provided attackers with indirect access to numerous unrelated websites without breaching each one individually.
Adform’s 2025 annual report states that the company served approximately 1.5 billion advertisements every day for around 1,800 customers across more than 180 countries. While those figures describe the company’s broader advertising platform rather than the specific incident, they illustrate how widely distributed the affected infrastructure could be.
The company has not disclosed how many websites actually loaded the compromised JavaScript file or how many visitors may have been exposed.
Malware Used Obfuscation and Browser Manipulation
Analysis of the captured script revealed two malicious code blocks appended to Adform’s legitimate JavaScript library, confirming that the Supply Chain attack had injected unauthorized code into a trusted shared resource.
The attackers obscured replacement wallet addresses using XOR-based obfuscation to complicate detection.
One component monitored clipboard activity, periodically examined copied content, and attempted to replace cryptocurrency wallet addresses with attacker-controlled alternatives. It also initiated outbound HTTP communication with an external server, transmitting information related to the webpage hostname and path.
The second component scanned webpage text, modified cryptocurrency addresses entered into form fields, and intercepted browser events including copy, cut, paste, and user input.
Researchers also found that the malware hooked browser value setters, allowing it to rewrite addresses even when websites inserted values programmatically.
Several Questions Remain Unanswered
Despite Adform’s rapid response, investigators have yet to determine several key aspects of the incident.
Unknown factors include:
- How attackers initially compromised Adform’s deployment infrastructure.
- How many customer websites served the altered JavaScript file.
- How many visitors were exposed.
- Whether any cryptocurrency transfers were successfully redirected.
- Who carried out the attack.
Adform stated it found no evidence that the malicious code transmitted visitors’ IP addresses or browsing information. However, the company acknowledged that technical analysis indicates such transmission may have been possible because portions of the malicious script were capable of initiating outbound communications.
Researchers also noted that associated infrastructure—including malicious URLs, domains, and IP addresses—showed no detections on public malware intelligence platforms when initially discovered, highlighting the campaign’s ability to evade traditional threat detection.
Supply Chain Security Faces Growing Challenges
The Adform incident illustrates the growing cybersecurity risks associated with third-party JavaScript libraries embedded across modern websites.
Advertising technology, analytics platforms, customer support widgets, and content delivery services routinely execute code directly within visitors’ browsers. When one of these shared services becomes compromised, attackers can potentially affect thousands of websites simultaneously without breaching them individually.
Security professionals increasingly recommend organizations implement defenses such as Subresource Integrity (SRI), Content Security Policy (CSP), continuous third-party script monitoring, and behavioral threat detection to reduce exposure to supply chain attacks.
The incident also reinforces the importance of verifying cryptocurrency wallet addresses immediately before authorizing transactions. Because browser-based malware can silently replace wallet addresses without obvious visual indicators, users should carefully compare the full destination address rather than relying solely on copied values.
As investigations continue, the Adform compromise serves as another reminder that supply chain attacks remain one of the most effective methods for cybercriminals seeking large-scale access through trusted digital infrastructure.
Like The Gignomist‘s coverage? Subscribe to our free newsletter for the latest technology news, AI breakthroughs, startup updates, cybersecurity insights, blockchain developments, gaming trends, and expert analysis from across the global innovation ecosystem.




