# trackpoint-async.js

Type: Technology

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/trackpoint-asyncjs
Canonical HTML page: https://getcyberbrief.com/entity/trackpoint-asyncjs

## Timeline

- **2026-08-01**: Public disclosure and media coverage — Kevin Beaumont publicly releases details of the attack; news outlets The Hacker News and unsafe.sh publish reports.
- **2026-07-27**: Malicious code injected into Adform's trackpoint-async.js — Attackers modify the JavaScript file to swap cryptocurrency wallet addresses. The script is served from s2.adform[.]net to customer sites.
- **2026-07-27**: Adform detects and removes the malicious code — Adform identifies the compromise, deletes the poisoned file, and begins notifying affected clients.
- **2026-07-27**: Adform issues cache-clearing advisory — The company warns that the altered file may remain in browser caches and recommends users clear their cache to prevent continued execution.
- **2026**: Kevin Beaumont observes ongoing malicious activity — Beaumont reports seeing the wallet-swapping behavior via Adform over the past week, extending beyond the initial remediation.

## Recent coverage (1 stories)

### Supply Chain Attack via Adform Script Evaded VirusTotal, Swapped 3 Cryptos
2026-08-02 00:17:19 · Sentiment: Bearish · Impact: 8/10 · Sources: 2

A web supply chain attack poisoned Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron addresses on any site using the script, evading all VirusTotal detections and highlighting gaps in browser-based threat detection.
Full story: https://getcyberbrief.com/story/adform-supply-chain-attack-crypto-swapping-cyber

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.