Adform JavaScript Supply Chain Attack: Crypto Wallet Addresses Replaced Through Compromised Script
ID: 6212a89f-47d4-567c-929c-7fc6e855e436
STIX ID: report--6212a89f-47d4-567c-929c-7fc6e855e436
Feed Name: CyberNexora News
### Executive Summary On July 27, 2026 attackers modified Adform’s shared JavaScript resource (trackpoint-async.js) in a supply-chain attack that injected in-browser malware to monitor and replace Bitcoin, Ethereum, and Tron wallet addresses (including clipboard and form inputs) with attacker-controlled addresses; Adform detected and removed the malicious script the same day, notified customers, and reported the incident while investigations into the full scope and potential financial impact continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
