I was helping a player named Ares with his server being attacked and spammed by someone exploiting the recently discovered eval exploit.
As I was telling him to add me on steam someone was repeatedly disconnecting me with the message "awww_:(" (pictured below) and giving me super admin.

I collected a console.log from him, helped him remove the exploit, and looked through it to see who could possibly be abusing it.
Here's the console.log: justfilehosting.space/download.php?f=vwuir (Posted with his permission)
I looked through it to see when the first instance of evidence of the exploiting was happening. Luckily, whoever was doing it made a couple mistakes in their coding before they actually did anything.
First connect request besides the host was from Biller (ID 43126, IP 179.197.0.97)
Second connect request was from Pipblade (ID 34102, IP 72.198.81.25)
Third request was from a person who disconnected before the exploiting started.
Fourth request was from Setro (ID 43991, IP 24.47.111.232)
One of those 3 people was using the exploit. I am not pointing fingers at any specific one of them. It's also possible none of them were actually the ones attacking the server, but I have my doubts.