This JWAD Alfredo something on Upwork contacted me for a job was pretty convincing asked me to clone a project and run it. Of course I asked cursor to check for malicious code and sure enough this repo was given with .env files containing base64 encoded malicious endpoints and the server allows it to run remote execution commands.
Be wary if anyone asks you to clone an open and public repo. Stay safe
https://bitbucket.org/pet_join/pet_shop/src/master/
Please send this to abuse@atlassian.com and they will take action on it. Note that the team will not reply back.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.