{"id":695,"date":"2026-08-03T16:43:22","date_gmt":"2026-08-03T11:13:22","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=695"},"modified":"2026-08-18T16:45:51","modified_gmt":"2026-08-18T11:15:51","slug":"adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/","title":{"rendered":"Adform Script Compromise Shows How Trusted Web Supply Chains Reach Endpoints"},"content":{"rendered":"<p>The Adform JavaScript supply chain attack shows how one compromised web dependency can expose visitors across unrelated websites. On July 27, 2026, Adform detected malicious code in technology used by client websites, contained the incident, and removed the code. The payload attempted to replace cryptocurrency wallet addresses while an affected page remained open.<\/p>\n<p>The attack required no executable download or malicious browser extension. The code arrived through a trusted JavaScript resource that websites loaded during normal browsing.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Endpoint Security with Hexnode UEM<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the compromised Adform script worked<\/h2>\n<p>Security researcher Kevin Beaumont linked the activity to trackpoint-async.js, an Adform tracking script served from s2.adform.net. Adform\u2019s implementation documentation confirms that websites can embed this resource for site tracking.<\/p>\n<p>Attackers appended an obfuscated, self-executing payload to the legitimate library. When a page loaded the compromised file, the code searched for Bitcoin, Ethereum, and Tron wallet-address patterns. It then attempted clipboard hijacking by replacing a copied address with an attacker-controlled value.<\/p>\n<p>Analysis also found logic that could rewrite wallet addresses displayed or entered on webpages. This increased the risk that users would approve a transfer after checking the address on the same compromised page.<\/p>\n<p>Adform said the code did not install software or establish persistence. It operated only while an affected page remained open. Because browsers can temporarily cache JavaScript, Adform advised people who visited affected websites on July 27 to clear their browser cache.<\/p>\n<h2>Why this attack matters to enterprises<\/h2>\n<p>The incident demonstrates the reach of compromised third-party scripts. A business may secure its own code and still expose visitors when an external analytics, advertising, chat, or payment dependency becomes malicious.<\/p>\n<p>Security teams should not treat a lack of persistence as a lack of impact. Browser-executed code can manipulate user actions and transaction details before the user closes the page.<\/p>\n<p>Because the activity operated inside the browser without installing software, incident responders may need to combine browser evidence, web application logs, network telemetry, and endpoint data. No single layer may provide a complete view of the exposure.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Explore the top cybersecurity challenges enterprises face and practical strategies to reduce cyber risk.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>How organizations should respond<\/h2>\n<p>Organizations that embedded the affected Adform technology should identify the pages that loaded it, review relevant access and transaction records, and determine which users visited them during the affected period. Teams should clear application, content-delivery, and browser caches where appropriate. Adform specifically identified July 27, 2026, as the date on which website visitors may have faced exposure.<\/p>\n<p>Security teams should inventory external JavaScript dependencies and assign an owner to each integration. They should also monitor unexpected changes to hosted scripts and establish rapid vendor-notification and removal procedures.<\/p>\n<p>Content Security Policy can help organizations control which external sources a website may load. Subresource integrity may also help with eligible static resources, although organizations must assess whether it suits scripts that vendors update dynamically.<\/p>\n<p>Users handling cryptocurrency or other irreversible transactions should verify destination details through an independent channel. Recopying an address from the affected page may not help if the page continues to rewrite it.<\/p>\n<h2>How Hexnode can support endpoint risk reduction<\/h2>\n<p>Hexnode complements secure web development by strengthening endpoint security and access controls. It can complement web security controls through centralized device management, endpoint telemetry, and documented threat-investigation capabilities. It should not be positioned as directly detecting or validating compromised third-party JavaScript.<\/p>\n<ul>\n<li><strong>Standardize browser configurations:<\/strong> Use Hexnode UEM to enforce Google Chrome administrative policies or enroll managed Windows devices into Chrome Browser Cloud Management (CBCM) to restrict unauthorized extensions and enforce baseline browser settings.<\/li>\n<li><strong>Maintain updated endpoints:<\/strong> Automate Windows OS patch deployment and configure updates for supported Windows applications available through the Hexnode Store.<\/li>\n<li><strong>Enforce compliance-based access:<\/strong> Integrate Hexnode UEM with Microsoft Entra <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-conditional-access\/\">Conditional Access<\/a> to use compliance data from enrolled Android, iOS, and macOS 11+ devices when controlling access to configured organizational resources.<\/li>\n<li><strong>Strengthen investigations:<\/strong> Use <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> to correlate endpoint telemetry, investigate suspicious activity, and perform documented response actions such as device isolation and file quarantine during security investigations.<\/li>\n<\/ul>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can a JavaScript supply chain attack affect a device without installing malware?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Malicious JavaScript can run inside the browser when a website loads a compromised external resource. It can manipulate page content, intercept user actions, or alter transaction information while the page remains open, even without installing software or creating persistence.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should enterprises check after a third-party script compromise?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Teams should identify where the script ran, determine which users and transactions faced exposure, disable the dependency, clear relevant caches, and preserve logs. They should also review Content Security Policy (CSP) and Subresource Integrity (SRI) configurations where applicable, along with supplier controls, browser policies, endpoint telemetry, and notification procedures.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The Adform incident shows that trusted browser dependencies can become attack paths without leaving persistent malware. Enterprises should inventory third-party scripts, monitor supplier changes, harden managed browsers, maintain endpoint visibility, and verify sensitive transactions outside the affected page.<\/p>\n<p>UEM, XDR, and access-control capabilities can strengthen endpoint governance and investigation. However, organizations must combine them with secure web-development practices and third-party script monitoring to address JavaScript supply-chain risk effectively.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Secure Your Web Supply Chain<\/h5><p>Detect compromised scripts, protect endpoints, and reduce supply chain risk with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Adform JavaScript supply chain attack shows how one compromised web dependency can expose visitors&#8230;<\/p>\n","protected":false},"author":6,"featured_media":698,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,14],"class_list":["post-695","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-supply-chain-attack","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Adform JavaScript Supply Chain Attack: Key Lessons<\/title>\n<meta name=\"description\" content=\"The Adform JavaScript supply chain attack hijacked crypto wallet addresses. Learn how enterprises can reduce browser and endpoint risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Adform JavaScript Supply Chain Attack: Key Lessons\" \/>\n<meta property=\"og:description\" content=\"The Adform JavaScript supply chain attack hijacked crypto wallet addresses. Learn how enterprises can reduce browser and endpoint risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-03T11:13:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:15:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Adform Script Compromise Shows How Trusted Web Supply Chains Reach Endpoints\",\"datePublished\":\"2026-08-03T11:13:22+00:00\",\"dateModified\":\"2026-08-18T11:15:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/\"},\"wordCount\":893,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Supply Chain Attack\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/\",\"name\":\"Adform JavaScript Supply Chain Attack: Key Lessons\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp\",\"datePublished\":\"2026-08-03T11:13:22+00:00\",\"dateModified\":\"2026-08-18T11:15:51+00:00\",\"description\":\"The Adform JavaScript supply chain attack hijacked crypto wallet addresses. Learn how enterprises can reduce browser and endpoint risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Adform Script Compromise Shows How Trusted Web Supply Chains Reach Endpoints\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Adform Script Compromise Shows How Trusted Web Supply Chains Reach Endpoints\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Adform JavaScript Supply Chain Attack: Key Lessons","description":"The Adform JavaScript supply chain attack hijacked crypto wallet addresses. Learn how enterprises can reduce browser and endpoint risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/","og_locale":"en_US","og_type":"article","og_title":"Adform JavaScript Supply Chain Attack: Key Lessons","og_description":"The Adform JavaScript supply chain attack hijacked crypto wallet addresses. Learn how enterprises can reduce browser and endpoint risk.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-03T11:13:22+00:00","article_modified_time":"2026-08-18T11:15:51+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Adform Script Compromise Shows How Trusted Web Supply Chains Reach Endpoints","datePublished":"2026-08-03T11:13:22+00:00","dateModified":"2026-08-18T11:15:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/"},"wordCount":893,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp","articleSection":["Identity Abuse","Supply Chain Attack"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/","url":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/","name":"Adform JavaScript Supply Chain Attack: Key Lessons","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp","datePublished":"2026-08-03T11:13:22+00:00","dateModified":"2026-08-18T11:15:51+00:00","description":"The Adform JavaScript supply chain attack hijacked crypto wallet addresses. Learn how enterprises can reduce browser and endpoint risk.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Adform-Script-Compromise-Shows-How-Trusted-Web-Supply-Chains-Reach-Endpoints.png?format=webp","width":1340,"height":700,"caption":"Adform Script Compromise Shows How Trusted Web Supply Chains Reach Endpoints"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/adform-script-compromise-shows-how-trusted-web-supply-chains-reach-endpoints\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Adform Script Compromise Shows How Trusted Web Supply Chains Reach Endpoints"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/695","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=695"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/695\/revisions"}],"predecessor-version":[{"id":701,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/695\/revisions\/701"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/698"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=695"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}