this post was submitted on 09 Jul 2023
3 points (100.0% liked)
Café
777 readers
4 users here now
Welcome to our virtual third place, The Café.
Come on in and make a new human connection over a cup of coffee (or Teh Tarik). This is a casual community, do whatever you want, share your oyen pics, your frustrations, and even organize a weekend picnic with the community. The world is your oyster.
Rules are simple, be kind and civil with each other. As with any other café, rude patrons will be kicked out.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
is it the lemon party picture?...........feels old.
welcome to pre-rickroll internet.
Ahh, that's what it called, no wonder it's somehow familiar.
now I'm hearing that the hack is being spread through direct messages as well.
as this seems to be a javascript hack, all admins logged on through any web ui (even the official one) are advised to not open dm's from unknown users.
as mobile apps differ from browsers, and shouldn't execute javascript directly, they should be less affected, but please take caution anyway for the time being.
edit: it seems lemmy.blahaj.zone has been hacked too. the malicious javascript has been detected in custom emojis and community description sidebars, so admins must watch out for new users who signup and immediately start posting custom emojis or opening new communities.
Merely open the dm? Or do we have to click the link for it to happen?
I think it is better to not open it at all (at least in the web browser, mobile apps seem to be okay, but nothing is really certain atm), as the malicious javascript seem to be connected to custom emojis and community descriptions in the sidebar (see my latest edit), so no clicking required.
Alright, got it. Thanks!
damn, i feel like we can check off one success criteria: suddenly so attractive for hacks.