Password-manager sign-in look-alikes — 1password-login.com and bitwarden-vault.org
Two freshly registered password-manager look-alikes, 1password-login[.]com (registered 2026-09-24) and bitwarden-vault[.]org (2026-09-23), serve copies of the vendors' web sign-in pages ('Login to 1password', 'Login to Bitwarden Web Vault') to harvest master passwords, the one credential that unlocks every other account a victim has stored. Both are registered at Dynadot, are served from 158.94.209[.]214 and use the nameserver pair coral.spicas[.]top / harbor.spicas[.]top. That nameserver pair is not a public DNS service: spicas[.]top was registered on 2026-08-03, has no website, and its nameservers run on the same servers as the lures. The same pair serves roughly 75 other domains, almost all look-alikes: crypto-wallet software (Ledger Live, Trezor Suite, SafePal, Exodus, Trust Wallet), blockchain explorers and DeFi dashboards (Tronscan, DexScreener, DefiLlama), online banking, and software downloads, plus newly registered look-alikes of ordinary businesses. Many of these hosts put a 'Security Check' interstitial in front of the kit or return an error page to automated visitors, so a benign-looking capture on this infrastructure is not evidence that the page is harmless.
Anchors
domain:1password-login.com OR domain:*.1password-login.com OR domain:bitwarden-vault.org OR domain:*.bitwarden-vault.org