cross-posted from: https://sh.itjust.works/post/923025
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.
It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.
https://pastes.io/f2avblo0ev
https://web.archive.org/web/20230710051744/http://zelensky.zip/
I had to use FireFox’s readability feature to even read the site. It’s like a ytmnd up in here.
Here is the raw text of and a link to an archive of zelensky dot zip.