Someone used my open source project to phish people | Hacker News
TL;DR AI
2 min readKey summary
An open-source tool was reportedly abused for phishing by creating many signups and workspaces, then sending large batches of invitation emails.
The attacker used an open signup flow and a verified email-sending domain, without needing a traditional exploit or breach.
Commenters debated whether this was a software vulnerability or simply abuse of weakly controlled product features.
The case shows how legitimate features can be repurposed for spam and phishing, creating reputational and security risk.



