Online ad firm Adform’s script compromised to steal cryptocurrency
Summary
Online advertising firm Adform experienced a supply-chain attack where malicious scripts were injected into its ad platform. These scripts replaced cryptocurrency wallet addresses copied by users to their clipboards with attacker-controlled addresses, aiming to steal funds.
IFF Assessment
FOE
This attack represents a direct threat to users by compromising a trusted platform to facilitate financial theft.
Defender Context
This incident highlights the risks associated with supply-chain attacks, where a compromise of a third-party service can have widespread consequences for end-users. Defenders should remain vigilant about the security of third-party scripts and services integrated into their platforms, and educate users about potential threats like clipboard hijacking.