> Made the mistake of clicking the link instead of going directly to the site like I normally would (since I was mobile).
Does anyone know how this attack works? Is it a CSRF against npmjs.com?
Does anyone know how this attack works? Is it a CSRF against npmjs.com?
It wasn't a single-click attack, sorry for the confusion. I logged into their fake site with a TOTP code.
Sorry for what you're going through.
You login with your credentials, the attacker logins to the real site.
You get an SMS with a one time code from the real site and input it to the fake site.
The attacker takes the code andc finishes the login to the real site.