Community Intel & Discussions
🚨 Critical Security Alert: Account Hijacking Risk (suppy.org)
Risk Category: Credential Harvesting & Fraudulent Resale
URLert.com has classified suppy.org as a high-risk platform involved in deceptive practices and credential harvesting. While the site presents itself as a modern marketplace for discounted AI subscriptions, it utilizes high-risk technical requirements that compromise the security of your personal and financial data.
- Session Token Harvesting: The platform explicitly requires users to provide their
__Secure-next-auth.session-token. Handing over this token is functionally equivalent to providing your plaintext password and allows the operator to bypass Multi-Factor Authentication (MFA), granting them full, authenticated access to your OpenAI or Anthropic accounts. - Fraudulent Pricing & "Carding": The site offers ChatGPT Plus for $0.80 USDT—a 96% discount from the $20 retail price. Such implausible pricing strongly suggests the use of stolen credit cards or exploited enterprise trials, which frequently results in permanent account bans for the end-user.
- Illegitimate Activation Methods: Official AI providers do not utilize "CDKs" (Content Delivery Keys). This terminology is used to mask unauthorized account-sharing schemes and API abuse.
- Irreversible Payments: By operating exclusively via cryptocurrency and Telegram-based support, the site ensures that victims have no recourse for refunds once their accounts are compromised or disabled.
Recommendation: Do not interact with this domain or provide any session tokens. If you have already shared a token with this site, log out of all active sessions on your AI provider's dashboard immediately and change your password to invalidate the compromised session.