Using Security Keys/FIDO2 instead of TOTP codes completely solves trivial phishing attacks like this one.