Discuss Scratch
- Discussion Forums
- » Advanced Topics
- » Custom project page colors/styles in ordinary scratch (plus more things)
- atomicbryght
-
Scratcher
100+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
look at this for more informationwait whatit literally just caused a scratchwide hacking inccedentlet us all agree to never speak of this againSpeak of what? The thing were supposed to speak of in this chat, which is css?
- MuricanStonkEmpire
-
Scratcher
56 posts
Custom project page colors/styles in ordinary scratch (plus more things)
I think they have patched this I got my account back after getting canvased
- TimothyLawyer
-
Scratcher
1000+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
- STebBerry
-
Scratcher
100+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
- Its_me_ryan368
-
Scratcher
18 posts
Custom project page colors/styles in ordinary scratch (plus more things)
This is bad…look at this for more informationwait whatit literally just caused a scratchwide hacking inccedentlet us all agree to never speak of this againSpeak of what? The thing were supposed to speak of in this chat, which is css?
- RealApplePieStudios
-
Scratcher
17 posts
Custom project page colors/styles in ordinary scratch (plus more things)
its really really bad, but they are already trying to contain and eliminate it, so avoid suspicious projects and you should be fineThis is bad…look at this for more informationwait whatit literally just caused a scratchwide hacking inccedentlet us all agree to never speak of this againSpeak of what? The thing were supposed to speak of in this chat, which is css?
- Spooky_Lukey
-
Scratcher
1000+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
the title says “plus more things”if they were referring to that why would thyey post it in a topic not about that exploit? this topic is about custom project styles so i assumed thats what he was talking aboutthey did not patch it, my chatroom still has a stylei think they are referring to this
Last edited by Spooky_Lukey (May 5, 2026 14:34:57)
- nembence
-
Scratcher
500+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
I think that refers to the CSS scrollingthe title says “plus more things”if they were referring to that why would thyey post it in a topic not about that exploit? this topic is about custom project styles so i assumed thats what he was talking aboutthey did not patch it, my chatroom still has a stylei think they are referring to this
This CSS thing is different from what the virus is using, this works as soon as the project loads but can't inject JavaScript (because it works in sanitized costumes), while the virus uses JavaScript and works only if you go to the costume editor (because it works by exploiting some code in the costume editor to inject an unsanitized costume into the page)
Last edited by nembence (May 5, 2026 14:48:52)
- CST1229
-
Scratcher
1000+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
(#397)its not, it affects an unrelated part of scratchit literally just caused a scratchwide hacking inccedentlet us all agree to never speak of this againSpeak of what? The thing were supposed to speak of in this chat, which is css?
(the css exploit is in scratch-svg-renderer, the xss exploit is in paper.js (what the costume editor uses))
Last edited by CST1229 (May 5, 2026 15:15:27)
- STebBerry
-
Scratcher
100+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
exactly. people are making it seem like this exploit is hacking people too(#397)its not, it affects an unrelated part of scratchit literally just caused a scratchwide hacking inccedentlet us all agree to never speak of this againSpeak of what? The thing were supposed to speak of in this chat, which is css?
(the css exploit is in scratch-svg-renderer, the xss exploit is in paper.js (what the costume editor uses))
- OrangeCat747
-
Scratcher
20 posts
Custom project page colors/styles in ordinary scratch (plus more things)
I'm bored of this “customization”,Custom project page colors/styles in ordinary scratch, etc… PEOPLE ARE MAKING VIRUSES!!… pls ban .svg files from scratch, images are .png or .jpg NO MORE!
- OrangeCat747
-
Scratcher
20 posts
Custom project page colors/styles in ordinary scratch (plus more things)
I'm bored of this “customization”,Custom project page colors/styles in ordinary scratch, etc… PEOPLE ARE MAKING VIRUSES!!… pls ban .svg files from scratch, images are .png or .jpg NO MORE!https://scratch.mit.edu/projects/1316167087
- cheese2_
-
Scratcher
16 posts
Custom project page colors/styles in ordinary scratch (plus more things)
Viruses oh no
- STebBerry
-
Scratcher
100+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
I'm bored of this “customization”,Custom project page colors/styles in ordinary scratch, etc… PEOPLE ARE MAKING VIRUSES!!… pls ban .svg files from scratch, images are .png or .jpg NO MORE!okay, did you not know that svg's are the ONLY way you can use vector in scratch? and it's not a virus, it's an exploit, and if you're talking about the thing people are using to hack accounts, that's a different bug from this. what scratch SHOULD do is just fix the sanitization. svg's are completely fine, and without svg's vector wouldn't exist. stop overreacting.
- cheese2_
-
Scratcher
16 posts
Custom project page colors/styles in ordinary scratch (plus more things)
So it's not a virus it's a hack
- Digitat321
-
Scratcher
21 posts
Custom project page colors/styles in ordinary scratch (plus more things)
i am pretty sure it was initially discovered in 2024 but has resurfaced againit literally just caused a scratchwide hacking inccedentlet us all agree to never speak of this againSpeak of what? The thing were supposed to speak of in this chat, which is css?
- STebBerry
-
Scratcher
100+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
I'm bored of this “customization”,Custom project page colors/styles in ordinary scratch, etc… PEOPLE ARE MAKING VIRUSES!!… pls ban .svg files from scratch, images are .png or .jpg NO MORE!AGAIN: okay, did you not know that svg's are the ONLY way you can use vector in scratch? and it's not a virus, it's an exploit, and if you're talking about the thing people are using to hack accounts, that's a different bug from this. what scratch SHOULD do is just fix the sanitization. svg's are completely fine, and without svg's vector wouldn't exist. stop overreacting.
edit: sorry if i sound rude, i was in a bad mood when i posted that
Last edited by STebBerry (May 5, 2026 18:23:30)
- nembence
-
Scratcher
500+ posts
Custom project page colors/styles in ordinary scratch (plus more things)
I think they should make sure that the costume editor uses the same sanitizer as the project playerI'm bored of this “customization”,Custom project page colors/styles in ordinary scratch, etc… PEOPLE ARE MAKING VIRUSES!!… pls ban .svg files from scratch, images are .png or .jpg NO MORE!AGAIN: okay, did you not know that svg's are the ONLY way you can use vector in scratch? and it's not a virus, it's an exploit, and if you're talking about the thing people are using to hack accounts, that's a different bug from this. what scratch SHOULD do is just fix the sanitization. svg's are completely fine, and without svg's vector wouldn't exist. stop overreacting.
- whitnlan000
-
Scratcher
31 posts
Custom project page colors/styles in ordinary scratch (plus more things)
I'm bored of this “customization”,Custom project page colors/styles in ordinary scratch, etc… PEOPLE ARE MAKING VIRUSES!!… pls ban .svg files from scratch, images are .png or .jpg NO MORE!https://scratch.mit.edu/projects/1316167087
This virus isn't really the same SVG tech. We are changing the SVG to edit the css of the page. They are making an SVG with seemingly random text, that could be injected to run JS.
- Discussion Forums
- » Advanced Topics
-
» Custom project page colors/styles in ordinary scratch (plus more things)