logo

Cybercriminals Abuse Vibe Coding Service to Create Malicious Sites

ID: 518f4c93-e9b7-5dc0-a84a-5c0aeffd6be5

STIX ID: report--518f4c93-e9b7-5dc0-a84a-5c0aeffd6be5

Feed Name: Proofpoint Blog

Threat Score
75/100

Date Published: 2025-08-20

Date Updated: 2026-04-28

...
...

Proofpoint researchers report that threat actors are abusing Lovable's AI-powered 'vibe coding' platform to rapidly create convincing malicious websites used in large phishing and crypto scam campaigns. Observed activity includes MFA phishing via AiTM (Tycoon PhaaS), credential and session-cookie harvesting, payment data collection (including SMS codes), and distribution of wallet-drainers and loaders; Proofpoint saw tens of thousands of malicious Lovable URLs and campaigns affecting thousands of organizations, and Lovable has implemented security protections and takedowns in response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.