A sophisticated supply-chain attack recently targeted the digital advertising sector, specifically impacting the ad-tech firm Adform. According to The Hacker News, malicious actors successfully compromised a JavaScript file hosted by the company. By altering this script, the attackers transformed it into a client-side mechanism capable of intercepting and rewriting cryptocurrency wallet addresses displayed on various websites using Adformβs services.
The breach, which was identified on July 27, 2026, posed a significant risk to end-users who may have copied wallet addresses for transactions while visiting affected web pages. Once the malicious code was live, it effectively performed a 'clipboard hijacking' maneuver, swapping legitimate destinations with those controlled by the threat actors. This tactic is designed to siphon funds away from legitimate entities and into the attackers' digital wallets.
Upon discovering the unauthorized code, Adform took immediate action to mitigate the threat by removing the malicious script from its servers. The company has since initiated communication with impacted clients and notified the relevant authorities to investigate the incident further. While the cleanup operation was swift, the incident highlights the ongoing vulnerabilities within advertising supply chains, where third-party scripts can be weaponized to target users across a wide array of high-traffic domains.
Reader Discussion & Insights