cross-posted from: https://quokk.au/c/fediverse/p/1066667/tesseract-dev-injects-malicious-code-into-browser-to-illegally-ddos-the-dbzer0-instance

As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.

you are viewing a single comment's thread
view the rest of the comments
[–] 6 points 21 hours ago (1 child)

You are on the programming.dev instance and if you go to their website it uses the default Lemmy-UI.

In the instance "sidebar" at programming.dev it says this:

🟩 Not a fan of the default UI? We have alternate frontends we host that you can view the same content from

  • Tesseract
  • Photon
  • Alexandrite
  • Mlmym (old reddit-like)
  • Voyager (mobile)

These are actual links but I just copied the text.

If you ever clicked a linkt here and are now using the subdomain to browse, you can probably figure out what UI you use. For example, Alexandrite would be https://a.programming.dev/

If you use https://alexandrite.app/ directly it can login to whatever instance you are on btw.

  • source
  • parent
  • hideshow 2 child comments