HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Adform Supply‑Chain Attack Injects Crypto‑Stealing Script into Global Ad Network

Adform’s JavaScript tracking file was trojanized to monitor visitors’ clipboard, replace cryptocurrency wallet addresses, and exfiltrate IP data. The incident highlights the need for robust vendor‑risk controls and continuous monitoring to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 01, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Adform Supply‑Chain Attack Injects Crypto‑Stealing Script into Global Ad Network

What Happened — A malicious JavaScript (trackpoint‑async.js) hosted on Adform’s ad‑delivery domain was altered to monitor visitors’ clipboard and replace cryptocurrency wallet addresses with those controlled by an attacker. The script also sent IP and referrer data to a command‑and‑control server. The malicious code was removed after discovery on July 27 2026.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a classic third‑party supply‑chain risk where a vendor’s component compromises downstream customers, a scenario SOC 2 vendor‑management controls are designed to detect and mitigate.
  • Continuous evidence of vendor‑risk assessments, monitoring, and remediation is required to satisfy the SOC 2 CC6.1 (Vendor Management) and CC7.1 (System Operations) criteria.

Who Is Affected — Digital advertising ecosystem: publishers, e‑commerce sites, SaaS platforms, and any web property embedding Adform’s scripts (spanning tech, retail, media, and finance sectors).

Recommended Actions

  • Update your vendor‑risk register to include Adform and any similar ad‑tech providers; assess their security posture and incident‑response capabilities.
  • Implement continuous monitoring of third‑party scripts (e.g., Subresource Integrity, CSP) and retain logs as audit evidence of control effectiveness.
  • Notify affected users, advise clearing browser cookies and cache, and review clipboard‑access policies.

Technical Notes – The compromised script was a JavaScript file served from s2.adform.net. It monitored the clipboard for Bitcoin, Ethereum, or TRON addresses and swapped them with attacker‑controlled wallets. Exfiltrated data included IP address, referring site, and URL path, sent to 84.32.102.]230:7744. The code was not flagged by VirusTotal at the time. Source: [BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →