Online ad firm Adform’s script compromised to steal cryptocurrency

Online ad firm Adform’s script compromised to steal cryptocurrency
Adform suffered a supply-chain attack that injected malicious JavaScript into its tracking library, enabling clipboard hijacking to replace Bitcoin, Ethereum, and TRON wallet addresses with attacker-controlled ones. Security researcher Kevin Beaumont exposed the issue after discovering the trojanized script on websites using Adform’s ad platform, and Adform later removed the code and said it had taken protective measures. #Adform #KevinBeaumont #trackpoint-async.js

Keypoints

  • Adform’s tracking script was compromised in a supply-chain attack.
  • The malicious code monitored clipboards for crypto wallet addresses.
  • Bitcoin, Ethereum, and TRON addresses were replaced with attacker-controlled wallets.
  • The injected script could also rewrite wallet addresses shown on web pages.
  • Adform removed the code and advised affected users to clear browser cookies.

Read More: https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/