Threat Intelligence Bearish 8

Supply Chain Attack via Adform Script Evaded VirusTotal, Swapped 3 Cryptos

A web supply chain attack poisoned Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron addresses on any site using the script, evading all VirusTotal detections and highlighting gaps in browser-based threat detection.

· 4 min read · Verified by 2 sources ·
Share

Key Takeaways

  • A web supply chain attack poisoned Adform's trackpoint-async.js to replace Bitcoin, Ethereum, and Tron addresses on any site using the script, evading all VirusTotal detections and highlighting gaps in browser-based threat detection.

Mentioned

Adform company Kevin Beaumont person Max Maass person VirusTotal company Bitcoin technology Ethereum technology ETH Tron technology trackpoint-async.js technology

Key Intelligence

Key Facts

  1. 1On July 27, 2026, attackers poisoned Adform's trackpoint-async.js file, causing it to replace Bitcoin, Ethereum, and Tron wallet addresses on any site that loaded the script.
  2. 2The malicious code operated entirely in the browser, intercepting addresses from both the clipboard and directly typed form fields, and persisted even after re-copying.
  3. 3Adform detected the compromise on July 27, removed the bad code, notified affected clients, and reported the incident to law enforcement, but warned users to clear caches because the file may remain cached.
  4. 4Independent researcher Kevin Beaumont disclosed the attack and noted that the compromised file evaded detection by all antivirus engines on VirusTotal at the time.
  5. 5Adform's tracking script can be deployed across entire websites, meaning the supply chain compromise potentially affected thousands of downstream sites.

Even if you notice the address is wrong and recopy the wallet, it keeps replacing it.

Kevin Beaumont Independent Security Researcher

During public disclosure of the Adform script compromise

Analysis

For cybersecurity teams, the Adform incident is a textbook supply chain attack with a pure browser payload that sidestepped every AV engine on VirusTotal. This deep dive breaks down the TTPs and the defensive failures that allowed a malicious script to rewrite crypto transactions on thousands of sites.

A sophisticated supply chain attack leveraged Adform's advertising technology infrastructure to covertly replace cryptocurrency wallet addresses across an unknown number of customer websites. Detected on July 27, 2026, the attackers modified a core JavaScript file—trackpoint-async.js, served from s2.adform[.]net—to intercept and rewrite Bitcoin, Ethereum, and Tron addresses both on the clipboard and in directly typed form fields. Adform quickly removed the malicious code, notified affected clients, and reported the incident to authorities, but the company cautions that the poisoned file may remain cached in users' browsers, prolonging the threat beyond the initial remediation.

Detected on July 27, 2026, the attackers modified a core JavaScript file—trackpoint-async.js, served from s2.adform[.]net—to intercept and rewrite Bitcoin, Ethereum, and Tron addresses both on the clipboard and in directly typed form fields.

The attack's mechanism is particularly insidious. Rather than merely altering copied addresses, the script continuously replaced any wallet string it recognized while the compromised page remained open. According to security researcher Kevin Beaumont, who publicly disclosed the incident, 'Even if you notice the address is wrong and recopy the wallet, it keeps replacing it.' This persistence made it nearly impossible for a user to complete a legitimate transaction without manually verifying the address on a separate, uncompromised device. A captured sample also confirmed that the script targeted form fields directly, circumventing clipboard-based protections entirely.

Because Adform's tracking code can be deployed across entire websites—not just individual pages—the compromise represents a broad supply chain threat. Any site embedding Adform's script on July 27 could have exposed visitors to the wallet-swapping behavior, regardless of the site's own security posture. This shared-resource vector allowed the attackers to reach downstream targets without breaching each site individually, echoing high-profile supply chain incidents in the software world. Notably, Beaumont reported that the malicious file and its associated infrastructure returned zero detections on VirusTotal at the time of analysis, indicating a significant gap in threat detection for browser-level compromises.

The immediate impact is financial: anyone who copied or entered a wallet address on an affected site during the window of compromise may have inadvertently sent funds to an attacker-controlled wallet. The three targeted cryptocurrencies—Bitcoin, Ethereum, and Tron—are among the most widely used, amplifying the potential losses. While no specific theft figures have been reported, the attack's wide distribution and stealthy design suggest a high potential for silent theft. Adform's advisory to clear browser caches underscores the subtle persistence: a cached malicious script can continue to execute even after the server-side fix, making user action essential for full remediation.

Beyond the immediate crypto threat, the incident exposes systemic vulnerabilities in the adtech ecosystem. Adform is a major player in programmatic advertising, and its scripts are integrated into thousands of publisher sites, e-commerce platforms, and content portals. A compromise at this level challenges the trust model that underpins digital advertising: if a single third-party resource can turn any site into a financial fraud vector, brands, publishers, and consumers alike must reassess the security of third-party dependencies. The attack also illustrates the evolution of web-based threats, where malicious code operates purely in the browser to manipulate user transactions without leaving traditional malware footprints.

What to Watch

Regulatory and industry responses may follow. Adform's proactive notification and cooperation with authorities demonstrate a responsible disclosure process, but the incident raises questions about the adequacy of code integrity checks, real-time monitoring, and subresource integrity (SRI) in third-party scripts. For investors and marketers, the long-term damage to trust in adtech supply chains could lead to stricter vendor assessments and a push for decentralized or self-hosted alternatives. Meanwhile, cybersecurity professionals will scrutinize the attack for lessons in detecting browser-based supply chain manipulations, which can easily evade network-based defenses.

Looking forward, this incident is likely to accelerate the adoption of integrity verification for all third-party web resources. Browser features like SRI could become mandatory for high-value sites, and cryptocurrency platforms may integrate wallet address verification tools directly into transaction flows. The attack also hints at a broader trend: as Web3 adoption grows, the intersection of traditional web infrastructure and decentralized finance creates novel attack surfaces that demand new defensive strategies. Adform's experience serves as a cautionary tale for any company that relies on shared, externally hosted scripts to reach millions of users.

Timeline

Timeline

  1. Kevin Beaumont observes ongoing malicious activity

  2. Malicious code injected into Adform's trackpoint-async.js

  3. Adform detects and removes the malicious code

  4. Adform issues cache-clearing advisory

  5. Public disclosure and media coverage

Sources

Sources

Based on 2 source articles

Cite This Page

"Supply Chain Attack via Adform Script Evaded VirusTotal, Swapped 3 Cryptos." Cyber Intelligence Brief, August 2, 2026. https://getcyberbrief.com/story/adform-supply-chain-attack-crypto-swapping-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.