Discuss Scratch

DHUCDH
Scratcher
6 posts

Can anyone explain what the "canvas virus" is?

I have seen alot of weird messages like this…

SCRATCHERS BEWARE, A group of hackers has created malware that we have dubbed ‘the canvas’ virus. The ‘Canvas’ virus lurks inside of projects of the infected, it tells you to ‘see inside’ and open the backdrop editor. DO NOT DO THIS, You will receive a message alerting you that you've been hacked, and will be signed out of your account. Your projects will be replaced with the infection and your profile description change. Be safe, stay alert, and report. Copy and paste to spread the word!!!

Its on most Studios and featured games with the studios being in the popular Studios like Friendship, Sugary sweets and more

WHAT IS THIS CANVAS VIRUS????????????????
ScodexPerson
Scratcher
1000+ posts

Can anyone explain what the "canvas virus" is?

There is a vulnerability where if you click ‘see inside’ and then click on the costume/backdrop editor, then it can actually excecute Javascript and on the offline editor, it can even do things like running malicious shell programs!

So please be aware of people asking to see inside!
DMRFan01
Scratcher
2 posts

Can anyone explain what the "canvas virus" is?

can it affect your projects?
ScodexPerson
Scratcher
1000+ posts

Can anyone explain what the "canvas virus" is?

DMRFan01 wrote:

can it affect your projects?
Yeah, it can delete your projects.
TimothyLawyer
Scratcher
1000+ posts

Can anyone explain what the "canvas virus" is?

it would be good to stop calling it a virus since it isn't
Go_With_The_FLO
Scratcher
1 post

Can anyone explain what the "canvas virus" is?

So does it take over your entire profile or just your projects? and is it possible for it to get other information and get into your device?
ArcOfTheDeep
Scratcher
2 posts

Can anyone explain what the "canvas virus" is?

ScodexPerson wrote:

There is a vulnerability where if you click ‘see inside’ and then click on the costume/backdrop editor, then it can actually excecute Javascript and on the offline editor, it can even do things like running malicious shell programs!

So please be aware of people asking to see inside!

On that note, do we have any examples of afflicted projects/accounts? Does this do the same thing when online/in-browser? What are the parameters as to when this is tripped? How would ScratchTeam fix this?
ArcOfTheDeep
Scratcher
2 posts

Can anyone explain what the "canvas virus" is?

TimothyLawyer wrote:

it would be good to stop calling it a virus since it isn't
It behaves like one. It's transmitted when the “evil javascript” contacts your profile, and makes copies of the virus.
Its-all-fake
New Scratcher
1 post

Can anyone explain what the "canvas virus" is?

Is there a way to notice if a project is infected?

(excess characters removed by moderator - please don't spam)

Last edited by Paddle2See (May 5, 2026 15:47:57)

coby316
Scratcher
23 posts

Can anyone explain what the "canvas virus" is?

I believe infected projects simply say “see inside and open backdrop”. Does anyone know if it has been fixed?
TimothyLawyer
Scratcher
1000+ posts

Can anyone explain what the "canvas virus" is?

it's actually not a virus, but a vulnerability/exploit

coby316 wrote:

Does anyone know if it has been fixed?

someone reported getting their account back after the exploit
filimanatorx1
Scratcher
4 posts

Can anyone explain what the "canvas virus" is?

Dude they kept changing my bio and posting projects with images of dead deer on them. Just delete all the projects infected, change ur password, and reset cookies.
eggcellentegg
Scratcher
1 post

Can anyone explain what the "canvas virus" is?

is there somewhere with an example of this “virus?” also, if i open the backdrop on an alt, will that have a risk of cross-contaminating my main account with the same email?
AndPherbCodes
Scratcher
500+ posts

Can anyone explain what the "canvas virus" is?

filimanatorx1 wrote:

Dude they kept changing my bio and posting projects with images of dead deer on them. Just delete all the projects infected, change ur password, and reset cookies.
No. Those projects were my greatest works. They can't be permanently gone.
fishfish6178
Scratcher
12 posts

Can anyone explain what the "canvas virus" is?

its a xss script that in certain projects can hack you if you see inside, scratch is known to have vulnerabilities regarding things like this.
I don’t know if its patched yet or how much of it is true though.
filimanatorx1
Scratcher
4 posts

Can anyone explain what the "canvas virus" is?

AndPherbCodes wrote:

filimanatorx1 wrote:

Dude they kept changing my bio and posting projects with images of dead deer on them. Just delete all the projects infected, change ur password, and reset cookies.
No. Those projects were my greatest works. They can't be permanently gone.

Well, if you really wanted to you could request accsess to the backup files if you ask an ST member. It could take months to receive it back tho seeing as the entire community is asking for their backup files.
T_plohj_pluh
Scratcher
42 posts

Can anyone explain what the "canvas virus" is?

AndPherbCodes wrote:

filimanatorx1 wrote:

Dude they kept changing my bio and posting projects with images of dead deer on them. Just delete all the projects infected, change ur password, and reset cookies.
No. Those projects were my greatest works. They can't be permanently gone.
then just save them as backup files
SakuraSerena
Scratcher
11 posts

Can anyone explain what the "canvas virus" is?

FOR THOSE OF US UNINFECTED, DOWNLOAD ALL OF YOUR PROJECTS!!!
_SMA4_
Scratcher
5 posts

Can anyone explain what the "canvas virus" is?

This is so stupid bruh
Sir_SweatsALot1
Scratcher
20 posts

Can anyone explain what the "canvas virus" is?

I made a project saying what i know about it:
https://scratch.mit.edu/projects/1316145873/

Powered by DjangoBB