I haven't run https://top-fwz1.mail.ru/js/code.js myself but a quick glance at it seems to indicate that it tries to harvest data from the page (references to "gender", "age", etc) and some shady-named variables like "bait". Also a function that fetches data from top-fwz1.mail.ru and then tries to submit a hidden 1px*1px form created in an iframe using this data and who knows what else.
All other archive.ph links from the poster seem to contain the same JS code from mail.ru, which makes it either doubly suspicious, or just means their computer or network is infected with something that injects it into their pages, who knows.
So it might just be a coincidence that mitchbob happens to be the one who posted a link where that script gets noticed. It's hard to know for sure of course.
There's no reason to believe that mitchbob was doing anything other than trying to be helpful to users. Tons of legit HN users do that. Let's not pick on one to make a witch out of.
>All other archive.ph links from the poster seem to contain the same JS code from mail.ru, which makes it either doubly suspicious, or just means their computer or network is infected with something that injects it into their pages, who knows.
This is top.mail.ru, a very common analytics platform not different from google analytics. Archive.today uses it.
What’s the purpose of this witch hunt? Xenophobic bullshit over the .ru TLD?
Because you are a xenophobic asshole and think all Russians are evil hackers trying to steal your data? It’s really sad to see such nastiness rearing it’s head on HN.
top.mail.ru is a huge analytics platform, exactly like google analytics, run by the biggest tech company in Russia.