top | item 45352610

Mass phishing emails pretending to be Y Combinator right now

65 points| Tremeschin | 5 months ago

Just received quite a smart phishing email/notification coming from "GitHub" by a user created less than a week ago (1) which is currently creating multiple issues a minute tagging many random usernames in a repository (2) with a "ycombinatornotify" app (3). The usual - asking to verify wallets, deposit for authorization as I've been selected for funding, etc. All issues contains the content of the email received, so I'll not paste them here (they're gone, but still, a bad idea to paste it).

- (3m in) They seem to have been rate limited or reached a target of 500 issues

- (5m in) Repository was just taken down, hope they automate back a warning

- They have typo-squatted the "y-comb[l]nator [dot] com" domain (with hyphen and L)

Quite urgent actions are needed to stop it, or warn the affected. Will update the submission with more information as time goes.

- [1]: https://github.com/ycombinato/

- [2]: https://github.com/ycombinato/rorg/

- [3]: https://github.com/apps/ycombinatornotify

31 comments

order
[+] tomhow|5 months ago|reply
Thanks, we're getting a lot of emails about this to [email protected].

The best email address for anything like this is [email protected], as they handle security issues for all of YC, including applications.

Thanks everyone for letting us know about this.

[+] britta|5 months ago|reply
For anyone at GitHub looking at this thread: please update your documentation page about how to report abuse (https://docs.github.com/en/communities/maintaining-your-safe...). I tried to follow the instructions, but I ran into a bunch of dead ends that slowed me down - I couldn't find the report abuse buttons for issues, comments, or repositories, only for the user profile page. I'm on Chrome on a Mac laptop, logged into GitHub.

Also, on the report abuse page that I got to from the user profile page, the green submit button is nearly hidden by the grey footer, even when I scroll the page around and complete the captcha.

[+] e1g|5 months ago|reply
To remove resulting notifications, see instructions here https://github.com/orgs/community/discussions/174283#discuss...

These spam repositories have been deleted, but I still had lingering notifications stuck on GitHub, and I couldn't see them in the UI to remove them (but the small blue notification dot was constantly on). The API hack resolved this problem.

[+] jakesomething|5 months ago|reply
Came here looking for this. Thank you - removed the annoying blue notification now.
[+] tfarias|5 months ago|reply
I got it too from yccombinator/-notification. They keep trying with different account/repo names.
[+] yb0000|5 months ago|reply
I almost thought it was real, since I’ve never received an actual email from YC. Can anyone share how to apply to YC and what the notification process looks like if you’re selected?
[+] wonger_|5 months ago|reply
How will this kind of attack be prevented in the future?
[+] domdfcoding|5 months ago|reply
Still at it with a different repo and app that hasn't (yet) been nuked, but I have reported to GitHub.
[+] domdfcoding|5 months ago|reply
The repo, the app, and the user account behind each have now all been nuked by GitHub.
[+] om8|5 months ago|reply
Also got it, found this thread by googling "ycombiinator"
[+] aanet|5 months ago|reply
I also received the notification / phishing attack.

Have reported it to Github

[+] Bender|5 months ago|reply
Be sure to email this to Daniel dang [email protected] and flag the email as high priority. Be sure to include all the email headers.

Also report it to github [1] and the Feds [2] in the off chance someone takes it seriously. Be sure to include all the email headers here too.

[1] - https://docs.github.com/en/communities/maintaining-your-safe...

[2] - https://www.ic3.gov/

[+] Tremeschin|5 months ago|reply
Thanks! Just wrote them a warning and forwared the original message.
[+] mavdotj|5 months ago|reply
Just got one a minute ago from ycombinator-notify/ycombinator and a bot named mail-notifaction-automatic
[+] DaxSudo|5 months ago|reply
Yea I just saw this notif on my GH app.
[+] shakibamoshiri|5 months ago|reply
Got it this morning both mail INBOX and Github notif
[+] sdpy|5 months ago|reply
I've received it from ycoommbinator/-co