logo

Adform compromised to serve crypto stealer via supply chain attack

ID: c8c381bf-57d5-5204-a06a-b6403a1b87c2

STIX ID: report--c8c381bf-57d5-5204-a06a-b6403a1b87c2

Feed Name: DoublePulsar

Threat Score
70/100

Date Published: 2026-07-30

Date Updated: 2026-08-06

Author: Kevin Beaumont

...
...

Malicious JavaScript (trackpoint-async.js) delivered via Adform's s2.adform.net modifies clipboard cryptocurrency addresses (BTC, ETH, TRX) to attacker-controlled wallets, polls every ~3 seconds to persistently replace recopied addresses, and exfiltrates user IP and referrer data to 84.32.102.230:7744. Observed IoCs include 84.32.102.230, s2.adform.net, and https://s2.adform.net/banners/scripts/st/trackpoint-async.js; the reporter notes the script was active for about a week and may be being removed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.