Tumblr Accounts Hacked By 'Racist' Javascript Virus – Thousands Affected

By Alexandra Burlacu | Dec 04, 2012 10:14 AM EST

Share This Story

  • Print
  • Email

A malicious worm has hit popular site Tumblr, posting a racist message to users' blogs without their permission.

In response, Tumblr is encouraging users who have seen the post to immediately log out of browsers that might be using the service.

Follow us

"We are aware that there is a viral post circulating on Tumblr. We are working to resolve the issue as swiftly as possible. Thank you," the company posted on Twitter.

The message posted on users' blogs is the work of a group that goes by the name of Gay Ni**er Association of America (GNAA), an "anti-blogging Internet-trolling organization," as Wikipedia defines it.

"[The] propagation of the most fu**ing worthless, contrived, bourgeoisie, self-congratulating and decadent bulls**t the Internet has ever had the misfortune of facilitating," the fake post described Tumblr. The message further accuses Tumblr users of being unoriginal, among others, and suggests they kill themselves.

"Attempting to delete these posts will delete your tumblr account, [so] by all means, go ahead!" concludes the post.

On Monday, Dec. 3, the GNAA tweeted via the @gary_niger account that its fake message had hit 3,800 unique Tumblr users. According to Gizmodo, that number was later raised to 8,600 affected users. While those tweets seem to have been deleted in the meantime, the @gary_niger handle is currently re-tweeting messages of support, as well as Twitter responses from angry Tumblr users.

The worm in question seems to have taken advantage of Tumblr's re-blogging feature, said Sophos security analyst Graham Cluley. The analyst explained in a blog post that any user who was logged into Tumbler would automatically re-blog the infectious post simply by visiting one of the offending pages.

Some users who were affected by the malware saw a pop-up message warning them that Tumblr would be undergoing maintenance on Dec. 4, starting at 1 a.m. The pop-up gave users two options: "Stay on Page" or "Leave Page."

If a user was not logged into Tumblr, visiting the infectious url would simply redirect them to their standard login page, Cluley further explained. If the computer was logged into Tumblr, however, the GNAA content was re-blogged on their Tumblr.

According to Tumblr, its engineers have managed to resolve the issue and get things back on track. The company further assures its users that no accounts have been compromised, and no action is necessary on their part. 

 

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Oppo Find 5Oppo Find 7 may boast Snapdragon 800 processor, whopping 4000mAh battery
HTC One Mini (M4) to be T-Mobile exclusive?
HTC Desire 200 entry-level Android smartphone leaks in video ahead of launch
Samsung prepping new Galaxy S4 variant with LTE-Advanced, doubling data transfer speeds
Tablet / Laptop / PC
iPad miniApple's next iPad mini 7.9 inch Retina display will be Samsung-made
Next generation Google Nexus 7 could launch in July for $229
Samsung Galaxy Note 8.0 LTE version landing exclusively on AT&T ‘in the coming weeks’
Acer Iconia W3 8-inch Windows 8 tablet ships next week
Gadgets
OUYA at E3 2013OUYA team and E3 organizers battle over parking lot space
Sony PlayStation 4 to be available at $399 at the end of this year
Mad Catz to unveil M.O.J.O. Android game console at E3 to challenge Ouya
Xbox One always-on requirements and used game policy - What you need to know
OS / Software
iOS 7iOS 7 Beta comes with a bug that opens the lock screen to access photos [Video]
Microsoft recovers missing Lumia 920 with prototype Windows Phone Blue
Android 5.0 Key Lime Pie, Motorola X Phone reportedly launching in October
Verizon pulls Android 4.1.2 Jelly Bean VRBMD3 update for Samsung Galaxy S3 due to LTE issue
Internet / Social Media
Facebook June 20 InviteWhat to expect from Facebook's June 20 event
WWDC 2013: OS X 10.9 Mavericks Safari is going to help you extend battery life
Samsung Galaxy S3 browser bug spikes data usage, slows loading times
Cisco appeals to European Commission to overturn Microsoft's 2011 acquisiton of Skype
What's App
InstagramInstagram may add video on June 20 to challenge Twitter's Vine
Microsoft Office now available for iPhones, but there's a catch
Vine for Android is no. 1 social app on Google Play Store
Chrome for Android updated with integrated Google Translate

DON'T MISS

Android 5.0 Key Lime Pie
Android 5.0 Key Lime Pie, Motorola X Phone reportedly launching in October
The highly-anticipated Android 5.0 Key Lime Pie will reportedly make its debut in late October
Nexus 7
Next generation Google Nexus 7 could launch in July for $229
New Google Nexus 7 for $229 in July of 2013? This could be another hit Android product for Google.
Samsung Galaxy S4 Active
Samsung Galaxy S4 Active to be AT&T exclusive at $199.99
Samsung Galaxy S4 Active is going to be launched on June 21 and if you are interested in this water-
Samsung Galaxy S4
T-Mobile drops Galaxy S4 price by $50 for one month
There is some good news for people who are on T-Mobile network and want to buy the new Samsung
iPad mini
Apple's next iPad mini 7.9 inch Retina display will be Samsung-made
Apple's new iPad mini will sport 7.9 inch Retina display with 2048 x 1539 pixel resolution. The
Low cost iPhone
Low cost iPhone reportedly shipping in large numbers
Is Apple scrambling to launch a low-cost iPhone in 2013?
Microsoft Office 365 Home Premium
Microsoft Office now available for iPhones, but there's a catch
Microsoft finally released its Office Mobile for iPhone as a free app, but there's a catch: it's
Nokia EOS Leaked
Nokia EOS 41-megapixel camera smartphone may debut on July 11
Nokia has a big event scheduled for July 11 in New York and the 'Zoom. Reinvented' teaser on the
HTC Tiara
Sprint HTC Tiara Windows Phone 8 smartphone leaks in PR image
The Sprint-bound HTC Tiara made its way to the Internet in an official PR image, complete with
Galaxy S2 Jelly Bean Update
Android 4.1.2 Jelly Bean finally available for AT&T Samsung Galaxy S2 (SGH-I777)
Android 4.1.2 Jelly Bean update finally comes via Samsung Kies to put Samsung Galaxy S2 users on
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics