Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Malicious repositories

Andrew Katsewich
December 4, 2024

No, https://www.atlassian.com/trust/report-abuse does not produce any results and no one replies there.
I have 2 repositories with malicious code. In the first one it's hidden on the right, in the second one it comes from an API as text and gets executed with eval().

 

https://bitbucket.org/bunney-bet-pro/casino/src/4d680db9640bde956bb4d73811e8143ad9cb5a23/server/routes.js#lines-60

 

https://bitbucket.org/rezoart_workspace/repo_ecommerce/src/3a6b728e110c03c0cea05982558b69cdd33ef4ed/server/controllers/product.js#lines-161

Thank you for cleaning this stuff promptly.

2 answers

1 accepted

3 votes
Answer accepted
Andy Heinzer
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
December 4, 2024

Hi @Andrew Katsewich 

The abuse mailbox is unable to reply.  But reports sent there should still be processed in due time.

That said I raised these repos to my security team and they have confirmed these have been taken-down from our site.

Thanks for reporting them to us.

Andy

Andrew Katsewich
December 4, 2024

Okay, I sent a message on Nov 26 with the first repo, and you saw it was still there today.

Thank you!

0 votes
Michael Yankelev
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 1, 2025

Another malicious repo found here: https://bitbucket.org/workspace1018/web3game/src/main/

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events