cross-posted from: https://sh.itjust.works/post/923025
lemmy.world is a victim of an XSS attack right now and the hacker simply injected a JavaScript redirection into the sidebar.
It appears the Lemmy backend does not escape HTML in the main sidebar. Not sure if this is also true for community sidebars.
https://lemmy.world/post/1290412?scrollToComments=true
The affected instances are coming back and the vulnerability being mitigated. Apparently no personal data was compromised. So you should be fine.