Security notice: unauthorized advertisements
Between April 2024 and 7 August 2026, transfaze.com was affected by third-party advertisements that we did not authorize. The most visible symptoms were pop-under ads on download pages and, for some users, browser push notifications appearing from our site even when the site wasn't open. The ads were served by the PropellerAds / Monetag network.
What happened
An attacker exploited a flaw in our download-management software that let anonymous requests reach admin-only endpoints. Using that access, the attacker inserted ad code into our ad-management system and, in April 2024, planted a browser "service worker" script that subscribed visitors' browsers to push-notification ads.
What did NOT happen
We have no evidence that any user files, upload contents, uploader credentials, or payment information were accessed. The vulnerability allowed modification of ad configuration; it did not give access to file storage or user-account contents.
What we've done
- Removed all injected ad code from our servers.
- Upgraded to the latest vendor build, which patches the underlying vulnerability.
- Added edge-level protection as defense-in-depth.
- Rotated administrative credentials.
- Enabled auditing to detect any re-injection.
What you should do
If you're still receiving push notifications from us, or seeing pop-under ads that appear to originate from our site, your browser has a cached copy of the malicious service worker. It will remove itself automatically the next time you visit transfaze.com — but if you want to speed it up:
- All browsers: open Settings → Privacy → Site Settings → transfaze.com, then choose "Clear data" and remove notification permission.
- Chrome / Edge: visit
chrome://serviceworker-internals/, findtransfaze.com, click "Unregister". - Firefox: visit
about:serviceworkers, findtransfaze.com, click "Unregister". - Safari (Mac): Preferences → Advanced → Show Develop menu, then Develop → Service Workers → transfaze.com → Delete.
If you have an account with us and would like to change your password as a precaution, you can do so at your account settings.
We are sorry this happened and thank the users who alerted us to the ads — your reports are what led us to identify and close the vulnerability. If you have questions, please contact us.