Adform, a prominent advertising technology firm serving approximately 14,000 businesses and controlling nearly 30% of the demand-side platform market, has experienced a severe supply chain compromise affecting its trusted ad-serving infrastructure. A security researcher named Kevin Beaumont discovered this breach and revealed that attackers exploited a widely used JavaScript file to silently infect visitors on thousands of downstream websites. This incident represents a classic textbook supply chain attack due to the reliance on a single tracking script across many businesses.
Once loaded, the malicious script acts as a clipboard hijacker, designed specifically to steal cryptocurrencies like Bitcoin, Ethereum, or Tron.
Because these addresses are long strings of random characters, most users paste them without double-checking, leading to funds intended for a legitimate recipient being redirected into a hacker's wallet. Every file, URL, domain, and IP address associated with the attack returned clean results when checked against major antivirus and threat intelligence platforms. The malicious code slipped into a legitimate, trusted advertiser's script, enabling it to evade standard security filters that usually flag suspicious third-party content.
For website operators using Adform's services, immediate action is crucial: audit third-party scripts, monitor outbound traffic to the identified attacker infrastructure, and rotate any exposed credentials. The beacon URL pattern, hxxp://84.32.102[. ]230:7744/p?h=




.webp&w=3840&q=75)
.webp&w=3840&q=75)





