FYI admins
cross-posted from: https://quokk.au/c/fediverse/p/1066667/tesseract-dev-injects-malicious-code-into-browser-to-illegally-ddos-the-dbzer0-instance
As part of the devs farewell message on their site, they have included malicious code to make each visitor sends 2,000 requests to the dbzer0 servers in an attempt to DDOS and take the instance offline.


The website has been taken down so that particular vector has been removed. The related startrek.website instance defederated from db0 and other instances have defederated from st.w due to all this.
The individual had at least 2 known alt accounts, so it’s likely they have more and will pop back up like a noxious weed.