Back to feed
Dev.to
Dev.to
8/1/2026
The headline needs to capture: Adform delivery script compromised, wallet addresses replaced (clipboard and screen), crypto clipper attack.

The headline needs to capture: Adform delivery script compromised, wallet addresses replaced (clipboard and screen), crypto clipper attack.

Original: Adform Delivery Script Compromised: Wallet Addresses Replaced on Clipboard and Screen

Short summary

A supply chain attack compromised Adform's trackpoint-async.js delivery script to inject an obfuscated JavaScript crypto clipper. The malicious code monitors clipboards for Bitcoin, Ethereum, and TRON addresses, replacing them with the attacker's wallet, and also rewrites addresses displayed on infected web pages. The attack exfiltrated victim IPs and browsing data to a remote server. CSP/SRI, script pinning, and hardware wallet verification are recommended mitigations.

  • Adform's ad tracking script compromised with obfuscated JS that replaces crypto wallet addresses on clipboard and DOM
  • Attack affected all downstream sites loading the modified trackpoint-async.js from s2.adform.net
  • Mitigations include CSP/SRI enforcement, self-hosted pinned scripts, and independent address verification

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more