As reported by Bleeping Computer, online advertising firm Adform experienced a supply-chain attack that injected cryptocurrency-stealing scripts into websites utilizing its ad platform, altering copied wallet addresses to ones controlled by an attacker.The attack exploited Adform's JavaScript tracking script, "trackpoint-async.js," which is embedded in numerous websites. Security researcher Kevin Beaumont discovered that this script monitored user clipboards for cryptocurrency wallet addresses, specifically for Bitcoin, Ethereum, and TRON. If detected, the script replaced the legitimate address with one belonging to the attacker, thereby redirecting any intended cryptocurrency payments. This method compromised end-user devices of downstream websites, meaning any site using Adform's platform could inadvertently infect visitors.The malicious code was appended to the legitimate library in an obfuscated form and could also rewrite wallet addresses displayed on web pages. Adform confirmed the incident on July 27, stating they removed the malicious code and implemented further protective measures. While the company asserts services are now safe, the investigation is ongoing. Visitors to affected websites on July 27 are advised to clear browser cookies.Source: Bleeping Computer
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
