“Pasting that little message will pick up a message or picture from whatever website the JavaScript is posting to,” Thakur said, adding that it doesn’t matter what type of browser people use.
The content is then posted on the users’ Facebook page, usually without their knowledge. It spreads further when their friends then click on those links, thinking that it was posted by the user on purpose.
Facebook said no user data or accounts were compromised during the attack.
It urged users not to cut and paste unknown code into a browser’s address bar. Users should always use an up-to-date browser and report any suspicious content on the site.
While the site scans malicious links against security databases and blocks those known to lead to spam, it can’t stop people from copying and pasting text manually into their web browser.
That’s where user vigilance comes in.
Thakur said users should be suspicious by the mere fact that someone is asking them to copy and paste something that Facebook is not permitting to be clickable directly.
Facebook said it built enforcement mechanisms to quickly shut down the malicious pages and accounts that attempt to exploit the vulnerability.
“Our team responded quickly and we have eliminated most of the spam caused by this attack,” Facebook said in a statement. “We are now working to improve our systems to better defend against similar attacks in the future.”
- New research challenges fears about AI in the classroom - February 5, 2026
- How the FY25 funding freeze impacts students across America - July 24, 2025
- ‘Buyer’s remorse’ dogging Common Core rollout - October 30, 2014