Spam & Phishing Protection for Sharetribe Marketplace
Budget: $30 – $250 USD
Title: Sharetribe Flex — Fix Marketplace Spam & Phishing Vulnerability
Overview:
We run a live marketplace built on Sharetribe Flex (React/Node.js). A bad actor recently exploited our platform by creating a fake account and using the transaction enquiry system to send phishing messages to 14 sellers, impersonating our support team and linking to a malicious site. We need a developer to close this vulnerability.
What happened:
New account signed up with no verification
Immediately used the enquiry/transaction message system to send phishing messages at scale
Messages contained an external malicious URL and impersonated "ReGEM Support Team"
What we need fixed:
URL/link filtering in transaction messages — detect and block external URLs in customer messages before they reach sellers
Rate limiting on enquiries — new accounts should not be able to send messages to multiple listings in rapid succession
New user restrictions — add a "probation window" (e.g. email-verified + X hours old) before a user can initiate transactions or send messages
Admin alert system — notify admin when suspicious message patterns are detected (bulk enquiries, URLs, specific keywords)
Keyword/pattern filtering — block messages containing known phishing phrases (e.g. "verify your identity", "complete within 24 hours")
Tech stack:
Sharetribe Flex marketplace (FTW-product template)
React 17 / Node.js / Express
Sharetribe Flex SDK + Integration SDK
Server-side middleware already in place
Requirements:
Proven Sharetribe Flex experience
Understand Sharetribe webhook system and Integration SDK
Server-side implementation only — no frontend changes needed
Deliver working code with brief explanation of the fix
Budget: Fixed price, open to proposals
Timeline: ASAP — this is a live security issue
Overview:
We run a live marketplace built on Sharetribe Flex (React/Node.js). A bad actor recently exploited our platform by creating a fake account and using the transaction enquiry system to send phishing messages to 14 sellers, impersonating our support team and linking to a malicious site. We need a developer to close this vulnerability.
What happened:
New account signed up with no verification
Immediately used the enquiry/transaction message system to send phishing messages at scale
Messages contained an external malicious URL and impersonated "ReGEM Support Team"
What we need fixed:
URL/link filtering in transaction messages — detect and block external URLs in customer messages before they reach sellers
Rate limiting on enquiries — new accounts should not be able to send messages to multiple listings in rapid succession
New user restrictions — add a "probation window" (e.g. email-verified + X hours old) before a user can initiate transactions or send messages
Admin alert system — notify admin when suspicious message patterns are detected (bulk enquiries, URLs, specific keywords)
Keyword/pattern filtering — block messages containing known phishing phrases (e.g. "verify your identity", "complete within 24 hours")
Tech stack:
Sharetribe Flex marketplace (FTW-product template)
React 17 / Node.js / Express
Sharetribe Flex SDK + Integration SDK
Server-side middleware already in place
Requirements:
Proven Sharetribe Flex experience
Understand Sharetribe webhook system and Integration SDK
Server-side implementation only — no frontend changes needed
Deliver working code with brief explanation of the fix
Budget: Fixed price, open to proposals
Timeline: ASAP — this is a live security issue