Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Someone is using your site to host possibly malicious scripts #4899

Closed
biltongza opened this issue Sep 17, 2020 · 1 comment
Closed

Someone is using your site to host possibly malicious scripts #4899

biltongza opened this issue Sep 17, 2020 · 1 comment

Comments

@biltongza
Copy link

I got sent a link in Facebook Messenger that looked like a legit youtube embed:
image

So I clicked on it. Instead of youtube I was met with this sketchy looking video player:
image

I inspected source and found my way to the sandbox that hosts this: https://codesandbox.io/s/295u7?file=/index.html

It looks like some nicely obfuscated shell code (?):

image

I'm not really sure what it does and I'm not sure what the correct way of reporting things like this is, so I figured I would start here.

@garethx
Copy link
Contributor

garethx commented Sep 17, 2020

Thanks, we've removed this sandbox.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants