Online ad firm Adform’s script compromised to steal cryptocurrency
Adform's advertising script was compromised in a supply-chain attack that injected cryptocurrency-stealing code. The malicious script intercepted wallet addresses copied to visitors' clipboards and replaced them with attacker-controlled addresses, affecting all websites using Adform's ad platform.
- Disclosed
- Last updated
- Blast radius
- Websites using Adform's ad platform; cryptocurrency users copying wallet addresses
- Ecosystems
- Attack vectors
- Affected entities
- AdformOnline advertising platform; ad script compromised
Adform, an online advertising firm, suffered a supply-chain attack targeting its ad delivery script. The compromise allowed attackers to inject malicious code that was distributed to websites using Adform's advertising platform.
The injected script performed clipboard hijacking, intercepting cryptocurrency wallet addresses that users copied and replacing them with attacker-controlled addresses. This attack vector targeted cryptocurrency users visiting websites served by Adform's ad network, potentially redirecting funds to attacker wallets.
The attack demonstrates the risk of compromised third-party scripts in the advertising supply chain, where a single compromised vendor can affect thousands of downstream websites and their visitors.
Indicators of compromise
- Packages
- Adform ad script
Remediation
- Audit and verify the integrity of Adform's ad scripts before deployment
- Implement Content Security Policy (CSP) headers to restrict script execution
- Monitor clipboard access and warn users before allowing clipboard modifications
- Use subresource integrity (SRI) checks for third-party scripts
- Implement real-time monitoring for unexpected script behavior changes
- Review and update vendor security requirements for ad platforms
Sources
- Online ad firm Adform’s script compromised to steal cryptocurrency · BleepingComputer
Cite this entry
"Online ad firm Adform’s script compromised to steal cryptocurrency." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/online-ad-firm-adform-s-script-compromised-to-steal-cryptocurrency-1o80lj
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/li-editor (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in mcp-mermaid (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in jest-canvas-mock (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-webgl-compute (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit