Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
ID: 816df1c4-2c8d-53e7-ae83-0d8d7e831301
STIX ID: report--816df1c4-2c8d-53e7-ae83-0d8d7e831301
Feed Name: CosmicBytez Labs
Threat Score
Adform detected on July 27, 2026 that an ad-serving JavaScript file had been tampered with to silently replace cryptocurrency wallet addresses in users' browsers, redirecting payments to attacker-controlled wallets; Adform removed the code, notified customers and authorities, and the report highlights risks of third‑party JavaScript and recommends SRI, CSP, script auditing, and real-user monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
