Affected Systems
Adform ad platform and all websites embedding Adform advertising scripts. Any site visitor copying cryptocurrency wallet addresses during the compromise window was at risk of clipboard hijacking.
Exploitation Status
Active exploitation confirmed. Supply-chain attack successfully delivered malicious JavaScript that replaced cryptocurrency wallet addresses in user clipboards with attacker-controlled addresses.
Business Impact
Websites using Adform ads unknowingly served malicious scripts to visitors, creating reputational risk and potential liability. End users who copied crypto wallet addresses during the attack window may have sent funds to attacker wallets. No CVE assigned. Scope and duration of compromise not publicly disclosed.
Urgency
🟠Within 24 hours
Recommended Actions
- Identify all web properties using Adform ad scripts and review access logs for the compromise period to assess visitor exposure
- Contact Adform directly for incident timeline, IOCs, and confirmation that malicious code has been removed from their platform
- Implement Content Security Policy (CSP) headers to restrict third-party script execution and consider Subresource Integrity (SRI) for ad platform scripts
- Alert users who visited affected properties during the compromise window about clipboard hijacking risk and advise verification of recent cryptocurrency transactions
- Evaluate ad platform vendor security posture and consider diversifying or isolating third-party advertising scripts in sandboxed iframes
