news.mlab.sh
Back to the feed
supply-chain

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

High
Image: The Hacker News
Summary

Adform, an advertising technology company, suffered a supply-chain attack where attackers injected malicious JavaScript code into their tracking script, allowing them to swap cryptocurrency wallet addresses across customer websites. The attack was detected on July 27, 2026, and involved a complex JavaScript payload that replaced addresses in both copied values and directly entered fields. While Adform found no evidence of IP address transmission, the potential for data exfiltration remains unclear due to a gap in the timeline. The incident highlights the risks associated with shared code deployments and the need for robust supply-chain security measures.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.