Mass phishing emails pretending to be Y Combinator right now
65 points| Tremeschin | 5 months ago
- (3m in) They seem to have been rate limited or reached a target of 500 issues
- (5m in) Repository was just taken down, hope they automate back a warning
- They have typo-squatted the "y-comb[l]nator [dot] com" domain (with hyphen and L)
Quite urgent actions are needed to stop it, or warn the affected. Will update the submission with more information as time goes.
- [1]: https://github.com/ycombinato/
[+] [-] tomhow|5 months ago|reply
The best email address for anything like this is [email protected], as they handle security issues for all of YC, including applications.
Thanks everyone for letting us know about this.
[+] [-] britta|5 months ago|reply
Also, on the report abuse page that I got to from the user profile page, the green submit button is nearly hidden by the grey footer, even when I scroll the page around and complete the captcha.
[+] [-] e1g|5 months ago|reply
These spam repositories have been deleted, but I still had lingering notifications stuck on GitHub, and I couldn't see them in the UI to remove them (but the small blue notification dot was constantly on). The API hack resolved this problem.
[+] [-] jakesomething|5 months ago|reply
[+] [-] gbrayut|5 months ago|reply
[+] [-] mulka|5 months ago|reply
[+] [-] tfarias|5 months ago|reply
[+] [-] yb0000|5 months ago|reply
[+] [-] wonger_|5 months ago|reply
[+] [-] domdfcoding|5 months ago|reply
[+] [-] domdfcoding|5 months ago|reply
[+] [-] rossant|5 months ago|reply
[+] [-] mulka|5 months ago|reply
[+] [-] om8|5 months ago|reply
[+] [-] unknown|5 months ago|reply
[deleted]
[+] [-] aanet|5 months ago|reply
Have reported it to Github
[+] [-] Bender|5 months ago|reply
Also report it to github [1] and the Feds [2] in the off chance someone takes it seriously. Be sure to include all the email headers here too.
[1] - https://docs.github.com/en/communities/maintaining-your-safe...
[2] - https://www.ic3.gov/
[+] [-] tomhow|5 months ago|reply
[+] [-] Tremeschin|5 months ago|reply
[+] [-] mavdotj|5 months ago|reply
[+] [-] its-all-waves|5 months ago|reply
[+] [-] muhuk|5 months ago|reply
[+] [-] DaxSudo|5 months ago|reply
[+] [-] Tremeschin|5 months ago|reply
[+] [-] shakibamoshiri|5 months ago|reply
[+] [-] unknown|5 months ago|reply
[deleted]
[+] [-] sdpy|5 months ago|reply