SitePoint hacked: Hashed, salted passwords pinched from web dev learning site via GitHub tool pwnage

SitePoint hacked: Hashed, salted passwords pinched from web dev learning site via GitHub tool pwnage

SitePoint, an Australian learn-to-code publishing website, has been compromised while promoting the book Hacking for Dummies on its homepage.


Reg reader Andy told us: "Got an email from SitePoint this morning saying that they had been hacked and some non-important (to them) stuff like names, email addresses, hashed passwords etc might have been stolen. Coincided with a big increase in spam that I've been getting but that's probably coincidence."

An email sent to SitePoint users and seen by The Register confirmed the hack, though at the time of writing, the company has not published anything about it on its website or social media accounts.


It blamed an unnamed "third party tool we used to monitor our GitHub account, which was compromised by malicious parties."

The email sent to users said, in part:
Support the originator by clicking the read the rest link below.