Someone Spammed My DEV Post. I Traced It to a Wombat.
Illustration generated for this article. Every prop is a finding: the sack of blank name badges is the Faker persona namespace, the rubber stamp is the inert tracking parameter, the three coins are the break-even, and the red yarn connects nothing because attribution failed. TL;DR — A spam comment on my article led to a TinyURL, a throwaway .store domain, and finally a legitimate SaaS product…
On September 1st, a spam comment appeared on a DEV post about migrating legacy LLM infrastructure to an AI gateway. The comment, which claimed to increase chances of getting interviews fast, led to further investigation revealing a TinyURL, a throwaway .store domain, and a legitimate SaaS product with an affiliate code. The commenter used a Faker.js-generated name and a 19th-century engraving of a wombat for a face.
The operation costs only three signups a year to maintain, ensuring its persistence. This spam campaign, while not malicious, violated DEV's terms of service and funneled revenue to an anonymous entity.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.