Security notice: unauthorized advertisements

Between April 2024 and 7 August 2026, transfaze.com was affected by third-party advertisements that we did not authorize. The most visible symptoms were pop-under ads on download pages and, for some users, browser push notifications appearing from our site even when the site wasn't open. The ads were served by the PropellerAds / Monetag network.



What happened


An attacker exploited a flaw in our download-management software that let anonymous requests reach admin-only endpoints. Using that access, the attacker inserted ad code into our ad-management system and, in April 2024, planted a browser "service worker" script that subscribed visitors' browsers to push-notification ads.



What did NOT happen


We have no evidence that any user files, upload contents, uploader credentials, or payment information were accessed. The vulnerability allowed modification of ad configuration; it did not give access to file storage or user-account contents.



What we've done



  • Removed all injected ad code from our servers.

  • Upgraded to the latest vendor build, which patches the underlying vulnerability.

  • Added edge-level protection as defense-in-depth.

  • Rotated administrative credentials.

  • Enabled auditing to detect any re-injection.



What you should do


If you're still receiving push notifications from us, or seeing pop-under ads that appear to originate from our site, your browser has a cached copy of the malicious service worker. It will remove itself automatically the next time you visit transfaze.com — but if you want to speed it up:



  • All browsers: open Settings → Privacy → Site Settings → transfaze.com, then choose "Clear data" and remove notification permission.

  • Chrome / Edge: visit chrome://serviceworker-internals/, find transfaze.com, click "Unregister".

  • Firefox: visit about:serviceworkers, find transfaze.com, click "Unregister".

  • Safari (Mac): Preferences → Advanced → Show Develop menu, then Develop → Service Workers → transfaze.com → Delete.


If you have an account with us and would like to change your password as a precaution, you can do so at your account settings.



We are sorry this happened and thank the users who alerted us to the ads — your reports are what led us to identify and close the vulnerability. If you have questions, please contact us.