Critical

Adform supply-chain attack replaced crypto wallet addresses

SCM feed for Latest
Actively Exploited

Overview

Adform, a digital advertising company, has fallen victim to a supply-chain attack that manipulated its JavaScript tracking script, known as 'trackpoint-async.js'. This script is widely used across various websites, allowing attackers to replace legitimate cryptocurrency wallet addresses with their own. As a result, any transactions made through these compromised wallets could redirect funds to the attackers instead of the intended recipients. This incident not only raises concerns about the security of digital advertising tools but also highlights the potential for significant financial losses for users and businesses relying on these platforms. Organizations using Adform's services should review their security practices and monitor for any unusual activity related to cryptocurrency transactions.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Adform's JavaScript tracking script (trackpoint-async.js)
  • Action Required: Organizations using Adform should review their security practices and monitor for unusual cryptocurrency transaction activity.
  • Timeline: Newly disclosed

Original Article Summary

The attack exploited Adform's JavaScript tracking script, "trackpoint-async.js," which is embedded in numerous websites.

Impact

Adform's JavaScript tracking script (trackpoint-async.js)

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations using Adform should review their security practices and monitor for unusual cryptocurrency transaction activity.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

New XCSSET variant targets macOS devs via compromised Xcode projects

BleepingComputer

A new variant of the XCSSET malware has emerged, specifically targeting macOS developers by exploiting compromised Xcode projects and GitHub repositories. This malware is designed to infiltrate the development environment, potentially affecting thousands of users who download these compromised projects. Researchers have identified that the malware can steal sensitive information, including user credentials and private data, which poses a significant risk to both developers and their end users. As this malware spreads, it raises concerns about the security of development tools and the integrity of software supply chains. Developers are urged to be vigilant about the sources of their code and to implement security measures to protect their environments.

Aug 4, 2026

Iran Cyberattacks Against Minnesota Water Systems

Schneier on Security

Recent cyberattacks appear to be targeting water systems in Minnesota as part of a broader campaign affecting at least seven states. Although initial reports suggest no significant damage, these incidents raise concerns about the security of critical infrastructure. Former President Trump has publicly dismissed the notion that Iran is behind the attacks, instead blaming Minnesota officials for incompetence. This situation highlights ongoing vulnerabilities in U.S. water systems, which could potentially be exploited by hostile actors. The implications of such attacks are serious, as they could disrupt essential services and compromise public safety.

Aug 4, 2026

Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

darkreading

Recent attacks have revealed a methodical approach by threat actors using social engineering tactics to compromise networks. The attackers employ various lures to deliver ScreenConnect, a tool that allows for remote access, ensuring they can maintain persistent control over affected systems. This type of attack can expose sensitive information and disrupt business operations, potentially impacting organizations across sectors. As these tactics evolve, it becomes increasingly important for companies to enhance their security awareness and response strategies to mitigate such risks. Users and organizations must remain vigilant against social engineering techniques that can lead to unauthorized access.

Aug 4, 2026

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Hackread – Cybersecurity News, Data Breaches, AI and More

The Shai-Hulud npm worm has resurfaced, infecting over 1,280 npm packages that collectively receive around 2 billion downloads each month. This malware is designed to steal sensitive credentials from various platforms, including npm, GitHub, cloud services, and continuous integration (CI) tools, in real-time. The worm spreads through Keyv and other related packages, posing a significant risk to developers and organizations that rely on these tools for their software development processes. With the potential for widespread credential theft, users need to be vigilant and consider enhancing their security measures to protect their accounts. The incident serves as a reminder of the vulnerabilities that can arise within popular development ecosystems.

Aug 4, 2026

Dem senators criticize Trump administration decisionmaking on AI security risks

CyberScoop

Five Democratic senators have expressed their concerns over the Trump administration's approach to managing artificial intelligence (AI) security risks. They argue that the administration has been inconsistent, sometimes too passive and at other times overreaching, which they believe has created an environment where China could gain an advantage in AI development. The senators are urging for a more balanced and proactive strategy to address the growing security challenges posed by AI technologies. This situation is critical as AI continues to evolve rapidly, impacting various sectors, including defense and cybersecurity. The senators' critique highlights the need for a clear and effective policy to mitigate potential risks associated with AI advancements.

Aug 4, 2026

Massive ChainDrop npm supply-chain attack infects hundreds of packages

BleepingComputer

A new self-propagating malware called 'ChainDrop' has infected over 1,300 packages in the Node Package Manager (npm) registry, which collectively see around 2 billion downloads each month. This attack allows the malware to spread rapidly across various software projects that rely on npm packages. Developers and companies using these compromised packages are at risk of introducing vulnerabilities into their applications. The incident raises significant concerns about supply chain security, as it demonstrates how a single attack can impact a vast number of users and systems. Those affected should take immediate steps to identify and remove the compromised packages from their projects to mitigate potential damage.

Aug 4, 2026