Replicated it, it's an XSS
Login to reply
Replies (5)
Nostr devs on top of things 🫡
Insane, primal just removed the lottie-player 
GitHub
Remove lottieplayer · PrimalHQ/primal-web-app@299a26d
Primal's web app for Nostr, as experienced on primal.net. - Remove lottieplayer · PrimalHQ/primal-web-app@299a26d
Yep, just discovered myself that this is the source of the issue: 
GitHub
Lottie player JS was compromised with a drainer. Check dependencies. · Issue #3127 · airbnb/lottie-web
AFFECTED VERSION DO NOT RUN THIS: @lottiefiles/lottie-player@latest/dist/lottie-player.js DO NOT know if other CDNS are also affected. UPDATE: Look...
Last time there was an xss vulnerability on nostr (anigma) lots of people leaked their nsecs