Dev.to
8/1/2026

The headline needs to capture: Adform delivery script compromised, wallet addresses replaced (clipboard and screen), crypto clipper attack.
Original: Adform Delivery Script Compromised: Wallet Addresses Replaced on Clipboard and Screen
Short summary
A supply chain attack compromised Adform's trackpoint-async.js delivery script to inject an obfuscated JavaScript crypto clipper. The malicious code monitors clipboards for Bitcoin, Ethereum, and TRON addresses, replacing them with the attacker's wallet, and also rewrites addresses displayed on infected web pages. The attack exfiltrated victim IPs and browsing data to a remote server. CSP/SRI, script pinning, and hardware wallet verification are recommended mitigations.
- •Adform's ad tracking script compromised with obfuscated JS that replaces crypto wallet addresses on clipboard and DOM
- •Attack affected all downstream sites loading the modified trackpoint-async.js from s2.adform.net
- •Mitigations include CSP/SRI enforcement, self-hosted pinned scripts, and independent address verification
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



