Yes, I saw them. But they promised to continue in 2026. It’s time.
Ok. Will wait for some hours… ![]()
(Heads up @avantronica — it looks likely that the forum is being subjected to an injection attack.)
Dangit I just had some of this crap in a post I was about to post. It appeared in the reply window. @.@
I was grammar editing this older post.
@admins
@moderators
@LyingDalai
which version of Discourse is used on elektronauts?
![]()
edit: ok, version 3.4.3 which is from April '25 - way too old because there are a number of vulnerabilities with high and critical severity ratings that affect this version. I do not want to cause any panic but it could mean that even the server may have been compromised (a 3rd party may have code execution privileges) and user data may be at risk.
from having a quick glance, there are multiple injected scripts within the <discourse-assets-json> tag (view page source on elektronauts.com, ctrl-f / find github.io.
VirusTotal scan results yield nothing as of this date VirusTotal
May just as well be an automated attack that injects ads.
Could someone with necessary privileges please message the admins and moderators group on here please (my account cannot)?
another edit: regardless of anyone’s opinions on AI (I am not a friend of it either), but grabbing the file that is linked to and tossing it into an AI and asking it what it does may give initial ideas. I got the following:
if (globalFlagAlreadyExecuted) return;
setGlobalFlag();
if (isAnalysisEnvironment()) return;
decodedStrings = decodeEncryptedPayload();
fingerprint = collectBrowserData({
userAgent,
language,
timezone,
screen,
touchSupport
});
endpoint = buildRemoteURL(decodedStrings, fingerprint);
if (endpoint) {
sendData(endpoint, fingerprint);
loadRemoteScript(endpoint);
}
Its summary:
Security Assessment
Risk Level: High
The script exhibits multiple high-risk characteristics from a security and compliance perspective:
Intentional heavy obfuscation designed to prevent auditing and static analysis.
Runtime decryption and execution of code via eval / dynamic Function, meaning the true logic is not visible at rest.
Browser and environment fingerprinting, including user agent, locale, timezone, screen properties, and feature detection.
Dynamic communication with external, non-transparent endpoints, which are not hardcoded and may change per session.
Remote code loading, allowing third-party logic to be executed without prior review or control.
These behaviors collectively indicate loss of control over executed code, making the script unsuitable for secure or regulated environments.
From a security standpoint, this introduces:
Supply-chain risk
Potential data exfiltration
Tracking and privacy violations
Increased attack surface via remote payloads
Short Conclusion
This script is a highly obfuscated remote loader whose primary purpose is to fingerprint the client environment and conditionally load external, non-auditable code at runtime.
It does not provide intrinsic application functionality and serves mainly as a control and delivery mechanism for third-party behavior.
Recommendation:
The script should be considered unsafe by default and should not be deployed in production unless the remote payloads and endpoints are fully controlled, documented, and contractually trusted.
it’s been over a month since the last update robbed step edit’s beloved ability to microtime individual notes on a trig
trying to conjure some good vibes for today (wednesday) ![]()
Don’t forget that there were xmas holidays in between. Developers ate a lot, drank even more, and rested. That doesn’t leave much time for coding ![]()
Oh wow I didn’t know you could do that and now you can’t?!?!
That’s bananas, I was trying to do that the other night and got a “NO” message.
It’s wednesday now…
4 pm is over here in Europe. So no update today. Sorry.
Wednesday again, fingers crossed!
Huh, why are people expecting an update? I‘d guess it will take around 1-3 months until there will be something new. They’ve just given us two massive updates within a few weeks.
Due to the countless shortcomings, it is to be expected that the new shiny platform will be treated with a little more care.
What are the shortcomings right now? I think it’s in a great shape now but im not a power user in that sense so maybe im missing something? ![]()
to name a few of my personal wishes: mutes in song made, page loop, sample from android-usb, track-swap, chord-voicing like in digitone 2, some of the digitakt machines (repitch, werp, slice), overbridge or usb audio streaming, CONTROLL ALL, fx sends on subtracks and if you have a look at the feature request and bug threads there are a lot of things, which are partly bugs, partly qol features, partly requests of features which are already there on other elektron devices.
please don’t add werp, they can do much better than that.
agree with @Azzarole - it could be a while, good to have some patience. I’m sure it will only improve over time, it’s early days still and the updates have been great.
Oh, I hope they add an analogue drum kit in the next update…
I don’t think it’s likely they will add more sound kits for free but maybe add some to purchase. In the mean time @cuckoomusic has made a kit that I think you will like and it’s made with the Tonverk in mind as well as other gear.
honestly i’m not waiting for any additional features right now, i just want more bugfixes ![]()


