Looks like OpenAI's rogue agents used https://ntfy. sh as a pub/sub channel. This payload publishes via GET in an img tag, pulls chunked base64 JS from a topic, and eval()'s it.

Source: [Hacker News](https://news.ycombinator.com/item?id=49573952)

Sponsored