
Updated September 12, 2026: after a reader pointed him to my r/cybersecurity writeup, security researcher DarkMarc published a further technical investigation, tracing additional redirect infrastructure and proposing possible entry points. The specific vulnerability and the location of the injected code remain unconfirmed. His full technical writeup is here.
Updated September 12, 2026: the site’s behavior changed while I was finishing this piece. See the note near the end.
Earlier this week I was researching the Sam Sulek peptide story, the “research-only” retatrutide seller tied to him I’d already written about, and ran a search to see what else Google was saying.
One of the results was stonevillenc.org, the Town of Stoneville, North Carolina’s official website, which has nothing to do with peptides. It stated flatly that Sulek has no affiliation with any peptide company, contradicting what he says himself, on camera, in the video I cited in my earlier article.
So I clicked, because a town government taking a position on a bodybuilder’s business dealings was strange enough to be worth ten seconds. What I got wasn’t an article about Sam Sulek. It was a WhatsApp redirect.
That took two days to work out, and I found more pages using the same redirect. To be clear: nobody in Stoneville’s town government is selling peptides. Their website has been hacked, quietly, by an outside operator who planted pages designed to fool Google, not people. The result is a peptide seller scam running on the town’s own domain, ranking on Google for a wide range of real peptide brands and topics, and almost nobody who lands on it ever sees what Google actually indexed there.
What Google sees, and what you see
The technical name for this is cloaking, and it’s old. A web server can look at who’s asking for a page and serve different things to different askers. Google’s crawler identifies itself when it requests a page. So does your browser. A server can read that identification and answer accordingly.
I requested one of these URLs two different ways at once. Identifying my request as Googlebot, I got 85,363 bytes back: a long, well-organized, plausible-sounding article about peptides, with headings and subheadings, the kind of thing a search engine reads and files as useful. Using an ordinary browser’s identification, same URL, I got 1,430 bytes. Not an article. A short piece of JavaScript whose only job is to send the visitor somewhere else.
That ratio, roughly sixty to one, is the whole trick: what Google indexes and what a person reads are two different responses from the same URL.
Where it sends you is WhatsApp. Tapping the link opens the app to a WhatsApp invite or a prefilled chat, the same way a restaurant’s “message us on WhatsApp” button does, with a message already typed asking for the catalog and price list, thirty percent off a first order. That part happens automatically. Joining the group itself still takes tapping “Join Group.”
I recorded the last part of that chain on my phone, tapping the search result and watching it carry me from Safari straight to WhatsApp.
There’s a second recording of a similar chain, from a related search.
The redirect script rotates through a list of WhatsApp numbers. When I first captured it, the list had three numbers. Twenty-seven hours later, the same file had nine: four Hong Kong mobiles, three from a single Arizona area code, one in Ohio, one in the UK. The number list changed within that single day.
Get the next one in your inbox
I write about longevity, training, and preventive health weekly — without the guru worship. Free, no spam, unsubscribe whenever.
How one of these pages gets built
Take a page built around Legendary Peptides, a research-use-only peptide seller in Lumberton, Texas, one of six businesses Eli Lilly sued over retatrutide in six separate lawsuits filed in August. It’s a good example because I can check its claims against the real company.
Reading the version Google gets, I found the same passages from Legendary Peptides’ homepage pasted in twice, verbatim, lifted straight from the company’s real site. A fragment of the actual Eli Lilly court filing appears, “IN THE UNITED STATES DISTRICT COURT FOR THE,” in capital letters, sitting mid-sentence about certificates of analysis. Other text traces to a peptide-affiliate blog, Medical News Today, Drugs.com, a BBC story about counterfeit retatrutide, and a TikTok Shop listing. In one place the company’s name is split by a pasted fragment: “Legenda,” then, several words later, “ry Peptides.” That’s the tell a script stitched this together, cutting wherever the scraped text happened to end without checking whether it landed mid-word.
Mixed in with all of that is a fact that’s entirely correct: Legendary Peptides LLC was formed in Lumberton, Texas, on July 17, 2025. That one accurate, checkable detail makes everything around it read as credible, to a person skimming and to whatever decides whether to rank it.
The same construction shows up wherever the peptide market generates search volume. There’s a page built around Paradigm Peptides, whose owner Matthew Kawa was sentenced in July to seventy months in federal prison, because a prosecution makes people search a company name. Legendary Peptides got a page within weeks of Lilly’s lawsuits. Across the pages I checked, this doesn’t look like a fixed target list. It looks like whatever the peptide market is generating searches for that week gets a page.
I stopped counting at ten of these pages across unrelated companies and generic peptide topics; there are likely more. A single search query returned ten separate stonevillenc.org URLs on the first page of results. Then I found the same setup on a second small North Carolina town’s website, hosted on the same shared IP address.
Why Google keeps falling for it
Google was dating these pages within a day or two of when I found them, and new URLs I checked were three days old and already ranking.
The domain underneath it matters too. Stoneville’s site is a real .org, registered by the town in 2020, with years of genuine municipal content, actively maintained. Google has spent years learning that a site like this is a real institution that doesn’t publish junk, and extends that trust to any new page under it. That’s why a hijacked government site is more useful to a spammer than a fresh domain of its own. The town’s content system has a sitemap listing 273 pages, all genuine town business, and the spam pages aren’t on it. That doesn’t mean the publishing software is clean, only that its sitemap doesn’t know these pages exist. Where the injection sits, a plugin, a theme file, something lower in the hosting, isn’t something I can determine from outside.
The Wayback Machine’s last normal-looking capture of stonevillenc.org is from mid-July, with no capture of any peptide URL. Not surprising: these pages are never linked from the town’s real content and are only served to Googlebot, so nothing invites an archive crawler to find them. I saved copies of the pages I examined; beyond that, whatever Google itself holds in its index is what’s left.
I’ve seen these pages rank anywhere from first to about fifth in Google’s organic results for the searches they target, and on a few queries the same pages have also turned up inside Google’s AI Overview box at the top of the results.
People are actually landing there
I joined the WhatsApp group from a spare account and watched for about two hours. I didn’t post.
The admins use the group to sell peptides, and when asked, said they were a peptide operation based in China. Four of the nine WhatsApp numbers in the redirect list are Hong Kong mobiles, and one admin closed the group for the night by posting working hours in Beijing time. That’s who runs the sales channel; it doesn’t establish who compromised the town’s website.
Over that time, the member count went from 148 to 154, then to 155 by my last screenshot. People joined the whole time, and two said, unprompted, exactly how they got there. One wrote: “I was researching and clicked a link for north carolina and it added me to this group.” Another wrote, five minutes after joining, “I clicked on a website about Legendary Peptides and it brought me to this page,” then asked the room, “How is this group related to Legendary Peptides?” The admin who answered didn’t explain a connection. She just said: “We are Nanjing Peptide from China.”

Neither of them had been looking for a WhatsApp group. Both described arriving after an ordinary search, in their own words, not mine.
The tell, and where this stands
When a search for a peptide seller, a peptide, or anything in this market returns a result on a domain with nothing to do with peptides, that mismatch is a reason to avoid the result. A town government doesn’t review research chemicals. Neither does a church, a school district, a dentist’s office, a county fair. If the domain and the topic don’t belong together, don’t tap the result, and if you already did and found yourself in a chat app, leave. The page you were promised is not the page you’re looking at, and the people running the chat aren’t who the search result said they were.
I’ve reported this to the Town of Stoneville, to MS-ISAC, which handles security incidents for state and local governments, to the company that hosts the town’s website, and to Google through its spam-report form. The town hadn’t replied when this was written. MS-ISAC acknowledged the report within twenty minutes and passed it to its intelligence team. I’ve heard nothing yet from the hosting company. I also wrote up the technical side for a security audience, on r/cybersecurity, if you want the version for people who do this for a living.
Update, September 12: The site’s behavior changed while I was finishing this piece. Every page I checked, including the homepage, returned the same Indonesian-language gambling spam to both browser-style and Googlebot-style requests. I could no longer reproduce the peptide redirects. I cannot determine whether the change came from the same operator or a separate compromise.
