The website icon has changed, name changed to Israel, and the site title now includes a slur.
Anyone, if you know anything, please let the rest of us know.
edit: Most things seem to be okay now.
Edit 2: we are under attack again.
Nice community you have here, would be a shame if something happened to it.
Hey! You’re not welcome here! Git. Shoo. Go on now!
The website is now redirecting to porn, it looks like a XSS injection.
Lemmy in general or just world?
just .world, it’s a JavaScript redirection though so that means Lemmy in general has an XSS vulnerability and this will happen on other instances too if an admin account gets compromised
Yeah on web it says Israel - N**ga style. I was not expecting that at all.
I really really hope my credentials aren’t compromised now.
Edit: I recommend logging out on the website if you’re logged in, just in case they messed with the JavaScript files to harvest login tokens/cookies/etc.
An
moderatoradmin account MichelleG posted a few strange things that have since been removed. One was titled “We’ve whitelisted Threads.net” and all the post said was “go cry.” They may have been hacked or their account was compromised.It would take more than a mod to do this. Maybe an admin was compromised though.
That’s a good point. I’m quite certain the account was MichelleG.
Admin account was compromised. Looks like they are working on it but it will take a bit to fix all the stupid that was done.
EDIT: Looks like things are starting to resolve.
EDIT 2: MichelleG account admin was restored and she posted and update but shortly after the changes happened again. Her account is likely still compromised with someone else accessing things via it.
EDIT 3: lemmy.world back online. MichelleG has again been removed as admin. Most things appear to have been cleaned up. Blocked instances still need to be fixed however.
It really wouldn’t hurt to have admins in different timezones as right now this hack could have been much worse, imagine everything gets deleted and the site redirects to CP, the reputation gets immediately destroyed.
The hackers however knew what they were doing, they seem to know Lemmy well enough and it’s curious that they targeted lemmy.world despite it being popular only among people already a bit familiar with Lemmy and the Fediverse. Other people would usually look at join-lemmy and lemmy.ml first.
It also will auto link you to lemonparty.