When logging into lemmy.world the banner now says “Israel - ni**a style” (full word unredacted) and it starts linking to lemon party and a bunch of other NSFW sites.

  • nosut
    link
    51
    edit-2
    10 months ago

    Yea. Looks like they are working on it:

    EDIT: Looks like things are starting to resolve.

    EDIT 2: MichelleG account admin was restored and she posted and update but shortly after the changes happened again. Her account is likely still compromised with someone else accessing things via it.

    EDIT 3: lemmy.world back online. MichelleG has again been removed as admin. Most things appear to have been cleaned up. Blocked instances still need to be fixed however.

      • nosut
        link
        4310 months ago

        Worse. Admin account. The MichelleG account is an admin and it appears that it was compromised and is what is causing all the problems. It looks like they have removed it from admin so things wont get worse but they will likely take a bit to find and repair all the stupid little changes that were made.

        • @dragontamer
          link
          1010 months ago

          The sidebar was changed.

          Obviously some javascript was installed to the frontpage that makes us redirect to lemon party (NSFW) ponographic site.

          Logo on top of the screen has changed, anti-Israel has been plastered all over the place.

          • @PabloPicasshole
            link
            810 months ago

            This is not inspiring confidence in their security. 2FA was off or was somehow circumvented.

            • @gkd
              link
              1310 months ago

              If a JWT token was stolen 2FA wouldn’t matter.

            • MysticJorge
              link
              110 months ago

              Encountered that too. Would it be recommended to change passwords and logins though?

              • @PabloPicasshole
                link
                110 months ago

                We’ll see what they say but never a bad idea. Hopefully logins are encrypted and salted but I don’t use this username or password anywhere else.

                • MysticJorge
                  link
                  110 months ago

                  That’s the ideal situation. It’s been restored and I’m yet to see anything related to ‘login credentials being compromised’ or an advice to change them but as you said, it’s not a bad idea. Safety first

        • Meldroc
          link
          310 months ago

          The tasteless redirect & site-title-change seems to have gone away. The admins have retaken the site, now just cleaning up the junior edgelord’s mess.

          • @darrsilOP
            link
            110 months ago

            Nope, it’s back.

    • @darrsilOP
      link
      210 months ago

      Not resolved, still getting redirects.

    • @Chocrates
      link
      110 months ago

      Is there a discord or something people are in?

      • nosut
        link
        310 months ago

        Not that I am aware of at least.

        • Vamp
          link
          910 months ago

          Yeah the admins have said they’re hands off and all but one person managing the world community isn’t active since ruud doesn’t check his notifications.

          Somewhat concerning tbh