Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Summary
Attackers compromised Adform, a digital advertising technology company, by injecting malicious JavaScript into one of their served files. This script would rewrite cryptocurrency wallet addresses in users' browsers, redirecting funds to the attackers' wallets. Adform detected the issue, removed the malicious code, and notified affected customers and authorities.
IFF Assessment
This incident involves attackers compromising a widely used advertising script to steal cryptocurrency, representing a direct financial threat to users.
Defender Context
This attack highlights the supply chain risks associated with third-party JavaScript libraries and advertising platforms. Defenders should be vigilant about monitoring scripts served by external providers and implementing integrity checks to detect unauthorized modifications. It also underscores the importance of user education regarding cryptocurrency transactions and verifying wallet addresses.