Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Malicious Repository

Michael Collins
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 16, 2026

It seems there is a spike in malicious repositories being uploaded to bitbucket servers. I wish to add another to the list.

Repository: https://bitbucket.org/lyntrex/trading-view

1. npm lifecycle hook (package.json line 62) - Executes malicious server code during npm install
2. VSCode/Cursor auto-run task (.vscode/tasks.json) - Auto-executes when folder is opened in VSCode/Cursor
3. Obfuscated backdoor (.vscode/spellright.dict) - 3,824 bytes of heavily obfuscated JavaScript

0 answers

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events