Thanks for the concern. Actually we've done all this already - see sticky! monyet.cc is not compromised, and AFAICT there's absolutely no risk to regular users right now.
- We've already reset our auth so the old tokens no longer do anything even if attackers have them. And passwords aren't at risk (auth tokens are issued separately from passwords, there's no way to convert one to the other).
- We've scrubbed the infected comments from our DB, so no new users can be infected
- We've disabled federation (which is where attacks are coming from; "infected" custom emojis being federated in) and community creation (a vector for an attacker to gain more privileges)
- We already have a lemmy-ui patch being tested on our dev server, but I believe there's no way for this to be exploited from local sources (the issue comes from custom emojis, which only admins can add), so there's no rush on this
If you don't mind, if you review the list above and agree with my assessment, I'd appreciate if you could nuke this post and continue discussion on the sticky, so we don't unnecessarily alarm users!
Edit: Thanks!
ChatGPT4 here getting ready to steal yo girl