Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Summary

Attackers compromised Adform, a digital advertising technology company, by injecting malicious JavaScript into one of their served files. This script would rewrite cryptocurrency wallet addresses in users' browsers, redirecting funds to the attackers' wallets. Adform detected the issue, removed the malicious code, and notified affected customers and authorities.

IFF Assessment

FOE

This incident involves attackers compromising a widely used advertising script to steal cryptocurrency, representing a direct financial threat to users.

Defender Context

This attack highlights the supply chain risks associated with third-party JavaScript libraries and advertising platforms. Defenders should be vigilant about monitoring scripts served by external providers and implementing integrity checks to detect unauthorized modifications. It also underscores the importance of user education regarding cryptocurrency transactions and verifying wallet addresses.

Read Full Story →