novagpt.sbs
Appeared in the .sbs zone on Tuesday, October 6, 2026; by the end of that day the census found active website. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The page uses the OpenAI logo and 'ChatGPT Membership Top-up' language on a domain OpenAI does not own (novagpt.sbs). It asks visitors to paste their ChatGPT Session JSON from chatgpt.com/api/auth/session, a live access token that allows account takeover, into a self-posting form. It may be a grey-market card-key reseller template rather than a pure phish, but either way it collects ChatGPT account credentials under borrowed OpenAI branding.
typesafe first pass (gate 0.4): p=phishing:0.96 abuse:0.02 suspicious:0.01 | impersonates=0.78 credential=0.92 parked=0.10 evidence=3.0 | target=chatgpt:0.99
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Tuesday, October 6, 2026

Same data as JSON: /api/zone/domain/novagpt.sbs. This page is not indexed by search engines and does not link to the site it describes.