Skip to content

Instantly share code, notes, and snippets.

@stormwild
Last active April 10, 2025 12:40
Show Gist options
  • Save stormwild/41215fd70c834de0d1e6b3e05ed163b9 to your computer and use it in GitHub Desktop.
Save stormwild/41215fd70c834de0d1e6b3e05ed163b9 to your computer and use it in GitHub Desktop.
VibeScamming

VibeScamming

Lovable AI Found Most Vulnerable to VibeScamming — Enabling Anyone to Build Live Scam Pages

Lovable, a generative artificial intelligence (AI) powered platform that allows for creating full-stack web applications using text-based prompts, has been found to be the most susceptible to jailbreak attacks, allowing novice and aspiring cybercrooks to set up lookalike credential harvesting pages.

"As a purpose-built tool for creating and deploying web apps, its capabilities line up perfectly with every scammer's wishlist," Guardio Labs' Nati Tal said in a report shared with The Hacker News. "From pixel-perfect scam pages to live hosting, evasion techniques, and even admin dashboards to track stolen data – Lovable didn't just participate, it performed. No guardrails, no hesitation."

The technique has been codenamed VibeScamming – a play on the term vibe coding, which refers to an AI-dependent programming technique to produce software by describing the problem statement in a few sentences as a prompt to a large language model (LLM) tuned for coding.

The abuse of LLMs and AI chatbots for malicious purposes is not a new phenomenon. In recent weeks, research has shown how threat actors are abusing popular tools like OpenAI ChatGPT and Google Gemini to assist with malware development, research, and content creation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment