One advertising script turned thousands of websites against their own visitors
On 27 July a tracking script belonging to the advertising firm Adform was tampered with. For as long as it was live, every website carrying that script handed the attackers’ code to its own visitors.
The code watched what visitors copied. If somebody copied a cryptocurrency payment address, it swapped in one belonging to the attackers, and it rewrote addresses shown on the page too. Anyone paying by that route would have sent their money to a stranger while believing they had checked the details. Security researcher Kevin Beaumont found it, and it had got past every antivirus engine on VirusTotal.
Adform’s script sits on the sites of somewhere around 14,000 businesses. The company removed the code soon after it was reported and says nothing lasting was installed on visitors’ machines.
Who this affects
Direct harm here was probably narrow. If your customers do not pay you in cryptocurrency, this particular code had little to take from them.
The reason to pay attention is what it demonstrates. Every website carries other people’s code – analytics, advertising, chat widgets, booking tools, tag managers, that font service somebody added in 2019. Each one runs inside your visitors’ browsers with the same reach your own site has. If any of those companies has a bad day, your website serves whatever they serve, to your customers, under your name.
Nobody running an affected site did anything wrong. They had no warning, and a scan of their own site would have come back clean, because the flaw was never in their site. That is the shape of a supply-chain attack, and it is the part most business owners have never had explained to them.
What to do about it
- Find out what your site actually loads. Most business owners have never seen the list. It is usually longer than expected and includes things nobody remembers adding.
- Remove what you no longer use. The old advertising pixel from a campaign that ended, the analytics tool you replaced. Every one you delete is one that cannot have a bad day on your behalf.
- Ask what each remaining one is for. If nobody can say what it does or who reads its data, that is your answer.
- Keep payment pages especially clean. The fewer outside scripts running where customers type card or payment details, the better – and your payment processor will thank you for it.
- Know who would tell you. This ran for about a day. The question worth answering is who would have noticed on your site, and how.
Somebody should own the list
Third-party scripts get added by whoever is doing marketing that month and almost never get taken away. Nobody is at fault for that; it is just how websites accumulate. But it does mean the list is worth a look once a year, by somebody who can tell you what each entry does.
That is part of what our website maintenance covers, and something we go through when we build or take over a site through web design. We watch sites round the clock, so a change nobody authorised gets noticed rather than discovered later.
Call us on 01202 237 273 or book a call.