Across the most recent 1 story covering Adform — 100% negative sentiment, averaging 8/10 impact.
This entity profile aggregates every story where the entity meets our minimum relevance
threshold before it is linked here — a story naming this entity only in passing, as
competitive context for an unrelated subject, does not qualify. That threshold exists
because earlier testing surfaced entity pages cluttered with tangential mentions: a story
about two unrelated companies merging could otherwise populate a third company's page
simply because it was named once for comparison, with no real event of its own. The
timeline below reflects genuine milestones and developments specific to this entity,
cross-referenced against the same source-verification standard applied to every story on
this site. Sentiment measures the directional read of each development for this entity
specifically, not the overall tone of the reporting, and impact weights how consequential
a development is rather than how widely it was syndicated across outlets.
Figures are computed live from our source-verified story record — see our methodology for how impact and
sentiment are derived.
Timeline
Public disclosure and media coverage
Kevin Beaumont publicly releases details of the attack; news outlets The Hacker News and unsafe.sh publish reports.
Malicious code injected into Adform's trackpoint-async.js
Attackers modify the JavaScript file to swap cryptocurrency wallet addresses. The script is served from s2.adform[.]net to customer sites.
Adform detects and removes the malicious code
Adform identifies the compromise, deletes the poisoned file, and begins notifying affected clients.
Adform issues cache-clearing advisory
The company warns that the altered file may remain in browser caches and recommends users clear their cache to prevent continued execution.
Kevin Beaumont observes ongoing malicious activity
Beaumont reports seeing the wallet-swapping behavior via Adform over the past week, extending beyond the initial remediation.
A web supply chain attack poisoned Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron addresses on any site using the script, evading all VirusTotal detections and highlighting gaps in browser-based threat detection.
This page surfaces every story mentioning Adform across our cybersecurity coverage. We track each entity's appearance over time so readers can trace how the narrative evolves — which developments are isolated incidents, which build into longer arcs, and which reframe how operators in the space think about the entity. Story selection uses the same multi-source verification gate applied across the rest of our coverage.
Read our editorial methodology for how we identify, deduplicate, and score entity references. Our glossary defines the technical terms used across stories on this page, and our trends index contextualizes individual developments against the longer-running cybersecurity beat. Cross-entity comparisons live on our compare view.
Entities only appear on this page once the classifier scores them at a minimum 35 percent
relevance to the story, filtering out passing mentions. According to that methodology,
reviewed July 2026, this follows multi-source corroboration standards recommended by
journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong on this page — a misattributed entity, a wrong stat, a broken source
link? Report a data issue.
What you see
What it tells you
Story count
Number of distinct stories where Adform was a primary or referenced actor.
Recency clustering
Whether mentions are concentrated in a recent window (a news cycle) or distributed (a sustained arc).
Sentiment distribution
Aggregate sentiment of the stories mentioning this entity, weighted by impact score.
Cross-niche links
When the same entity surfaces in our sibling networks, we link to those views to enrich context.