Post #4131807
2026-07-27 07:48 UTC
Looks like #adform got compromised. It is shipping a malware-laced tracking script that is replacing crypto wallet addresses in the users clipboard. Recommend disabling adform includes in your websites. Sample: https://gist.github.com/malexmave/8ef5eabc7b6866698f1ea8a811c75b57
Analysis by Claude: https://claude.ai/share/5c751f9c-2bae-4835-8dff-fcbebf66d5dc
#threatIntel
Replies (1)
-
@hacksilon@infosec.exchange 2026-07-27 07:52
It also never ceases to amaze me that people will compromise a widely used library / service and then ship a highly specific Bitcoin malware instead of a more general infostealer or something like that. If you have that kind of access, why burn it on something dumb? I mean, I guess I'm happy they did, but still. Also, Permission Policy works - on the site I was doing incident response for, the malware was actually blocked by the Permission Policy disabling clipboard access requests.