DEV Community

Someone Spammed My DEV Post. I Traced It to a Wombat.

Don Johnson on September 10, 2026

Illustration generated for this article. Every prop is a finding: the sack of blank name badges is the Faker persona namespace, the rubber stamp ...
Collapse
 
francistrdev profile image
FrancisTRᴅᴇᴠ •

Great investigation from a spam comment that we all see at some point! Good work Don :)

Collapse
 
thomasbnt profile image
Thomas Bonnet •

Awesome post, I liked this investigation!

Collapse
 
vinhnguyenthanhdn profile image
Vinh Nguyen •

Two comments of this exact template landed under unrelated DEV posts today, and both shorteners put me back on your host: tinyurl.com/ykka56ap to zenviapro.store/massapply?along=zowie, tinyurl.com/42jatv3w to zenviapro.store/ainotetaker?dress=hovel. The parameter name is randomized, not only its value — whose, along, dress, and madly across four samples, the last one being the link marianhuels45529 dropped in this very thread. That extends your inert-prop finding rather than just confirming it: your sweep held the key fixed and varied the value, and nothing moved because the key is generated per comment too, so it is uniqueness noise rather than segmentation and no value of it could ever have routed anything. The other thing four samples show is a second route. /ainotetaker answers today and 302s to bluedothq.com/?via=us, a different product with a different Rewardful token, so this is not one domain and one route but a small rack with at least two products on it, and the three-signups-a-year break-even becomes a per-product figure.

Collapse
 
gnomeman4201 profile image
GnomeMan4201 •

Really solid investigation, especially the fact that you documented the false attribution lead instead of quietly dropping it.

One small evidentiary distinction I’d make: showing that Jaylon, Stiedemann, and Terry all exist in Faker datasets demonstrates that the username is consistent with automated generation, but it doesn’t quite prove Faker provenance from a single account.

That argument would get much stronger if you found multiple accounts using the same {firstName}_{lastName}-{lastName}{NN} structure with tokens mapping back to the same locale or generator family.

That aside, the preservation, redirect tracing, IOC work, and disconfirmation section are unusually well done for a spam investigation.

Collapse
 
alexshev profile image
Alex Shev •

The cost model is the sharp part: low conversion economics explain why weak attribution does not make the operation irrational. A useful defensive extension would be to record the redirect chain and account signals as structured evidence, so moderation has a reusable pattern instead of a one-off anecdote.

Collapse
 
onizuka profile image
Onizuka •

The break-even math is the part that actually matters — three signups a year to cover domain + shortener costs means the economics are basically unkillable. I ran similar attribution on spam hitting my own API docs last year and hit the same wall: the redirect chain resolves, the affiliate code resolves, but the human behind the faker.js persona never does. The wombat engraving is a nice touch but the real finding is that "who" is a dead question when the cost of being nobody is $2.

Collapse
 
earlgreyhot1701d profile image
Earl Grey •

The game is afoot! Well played.

Collapse
 
zaradevto profile image
Zara •

great inestigation and great title lol