[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fioFf0OZPlihw3PnJhn4vaKvTqJvqEGDPyv8fAAgMCSM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"4ca9f640-cc7e-4117-9cde-acfe8559d3c1","poisoned-ad-script-hijacks-crypto-wallet-addresses-across-multiple-sites","383ee51b-244b-47b7-a1cd-e0795e424eaa","Poisoned Ad Script Hijacks Crypto Wallet Addresses Across Multiple Sites","Attackers compromised a trusted third-party JavaScript file served by Adform, a widely used advertising platform, turning it into a real-time crypto address hijacker across all customer websites that loaded the script. This is a classic supply chain attack: rather than targeting individual sites, adversaries exploited a single upstream vendor to achieve broad reach with minimal effort. The malicious code silently swapped legitimate cryptocurrency wallet addresses, meaning victims had no visual warning that their funds were being redirected. This incident underscores the critical risk of implicitly trusting externally hosted scripts, which inherit the attack surface of the vendor's entire infrastructure.","**Immediate actions:**\n- Audit all third-party JavaScript dependencies and verify their integrity using Subresource Integrity (SRI) hashes.\n- Instruct end-users and internal teams to clear browser caches and verify wallet addresses through an independent source before completing any cryptocurrency transaction.\n\n**Long-term improvements:**\n- Implement a Content Security Policy (CSP) to restrict which external scripts are permitted to execute on your web properties.\n- Establish a formal third-party vendor risk management program that includes periodic security assessments of all script and CDN providers.\n- Self-host or pin critical third-party scripts where possible, and route updates through an internal review and approval process.\n\n**Detection measures:**\n- Deploy real-time script integrity monitoring tools (e.g., PerimeterX, Reflectiz, or custom hash checks) to alert on unexpected changes to loaded JavaScript files.\n- Enable detailed client-side logging and anomaly detection to identify unusual DOM manipulation or form-field modification activity across customer-facing pages.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST CSF DE.CM-4: Malicious code detection","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","OWASP Top 10 A08:2021 – Software and Data Integrity Failures","W3C Subresource Integrity (SRI) Specification","GDPR Article 32: Security of Processing (vendor-sourced data exposure risk)","ITIL Service Configuration Management: Third-party asset tracking","published","2026-08-01T10:20:35.76244+00:00","2026-08-01T10:20:35.637+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fhackers-poison-adform-script-to-swap.html","hackers-poison-adform-script-to-swap-crypto-wallet-addresses-across-customer-sit-0fa86a","Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"f5e392e1-3964-441a-8ae0-c547ff9af5d7","2026-08-01","afternoon","ThreatNoir Weekend Brief — August 1","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-01\u002Fthreatnoir-afternoon-brief-2026-08-01.mp3"]