Adform, a leading player in the advertising technology industry, recently experienced a significant supply chain compromise that allowed attackers to use its ad-serving infrastructure for malicious purposes. Affecting approximately 14,000 businesses and nearly 30% of the demand-side platform market, this breach turned the platform into a vehicle for distributing malware designed to steal cryptocurrency. Security researcher Kevin Beaumont uncovered that attackers had infiltrated a commonly used JavaScript file, impacting thousands of websites. The compromised script, hosted on Adform's domain, is embedded on numerous client websites to track advertising performance. This widespread use meant that a single compromised file could potentially affect millions of users, turning this incident into a classic example of a supply chain attack.

Once a user visited a site using Adform’s tracking pixel, their device could unknowingly download the malicious code. This malware acts as a clipboard hijacker, continuously scanning for Bitcoin, Ethereum, or Tron wallet addresses and replacing them with attacker-controlled addresses. Given the complexity of cryptocurrency addresses, users often paste them without verifying, which allows the redirection of funds to attackers. Even if users notice and attempt to correct the address, the malware simply replaces it again in subsequent polling cycles.

Beyond financial theft, the malware also collects data by recording the victim’s IP address, the website, and the specific URL path visited, sending this information to an attacker-controlled server. This data helps attackers understand the reach and effectiveness of their spread. The incident went largely undetected as the malicious code was embedded in a legitimate script from a trusted source, bypassing standard security measures.

As of now, there has been no official confirmation from Adform regarding notifications to affected clients or a public disclosure. However, signs indicate that the malicious code is being removed, suggesting awareness of the breach by either Adform or the attackers. Website operators using Adform’s services are urged to take immediate action by auditing third-party scripts, monitoring outbound traffic, and rotating any potentially compromised credentials.