Adform Supply‑Chain Attack Injects Crypto‑Stealing Script into Global Ad Network
What Happened — A malicious JavaScript (trackpoint‑async.js) hosted on Adform’s ad‑delivery domain was altered to monitor visitors’ clipboard and replace cryptocurrency wallet addresses with those controlled by an attacker. The script also sent IP and referrer data to a command‑and‑control server. The malicious code was removed after discovery on July 27 2026.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a classic third‑party supply‑chain risk where a vendor’s component compromises downstream customers, a scenario SOC 2 vendor‑management controls are designed to detect and mitigate.
- Continuous evidence of vendor‑risk assessments, monitoring, and remediation is required to satisfy the SOC 2 CC6.1 (Vendor Management) and CC7.1 (System Operations) criteria.
Who Is Affected — Digital advertising ecosystem: publishers, e‑commerce sites, SaaS platforms, and any web property embedding Adform’s scripts (spanning tech, retail, media, and finance sectors).
Recommended Actions
- Update your vendor‑risk register to include Adform and any similar ad‑tech providers; assess their security posture and incident‑response capabilities.
- Implement continuous monitoring of third‑party scripts (e.g., Subresource Integrity, CSP) and retain logs as audit evidence of control effectiveness.
- Notify affected users, advise clearing browser cookies and cache, and review clipboard‑access policies.
Technical Notes – The compromised script was a JavaScript file served from s2.adform.net. It monitored the clipboard for Bitcoin, Ethereum, or TRON addresses and swapped them with attacker‑controlled wallets. Exfiltrated data included IP address, referring site, and URL path, sent to 84.32.102.]230:7744. The code was not flagged by VirusTotal at the time. Source: [BleepingComputer