Just received quite a smart phishing email/notification coming from "GitHub" by a user created less than a week ago (1) which is currently creating multiple issues a minute tagging many random usernames in a repository (2) with a "ycombinatornotify" app (3). The usual - asking to verify wallets, deposit for authorization as I've been selected for funding, etc. All issues contains the content of the email received, so I'll not paste them here (they're gone, but still, a bad idea to paste it).
- (3m in) They seem to have been rate limited or reached a target of 500 issues
- (5m in) Repository was just taken down, hope they automate back a warning
- They have typo-squatted the "y-comb[l]nator [dot] com" domain (with hyphen and L)
Quite urgent actions are needed to stop it, or warn the affected.
Will update the submission with more information as time goes.
- [1]: https://github.com/ycombinato/
- [2]: https://github.com/ycombinato/rorg/
- [3]: https://github.com/apps/ycombinatornotify
rolph•1h ago
tomhow•1h ago
rolph•57m ago
either its something i have changed on this particular agent, somthing changed on HN, or a newly aquired feat due to accumulated X.P.
thanx for pointing at it.