No, https://www.atlassian.com/trust/report-abuse does not produce any results and no one replies there.I have 2 repositories with malicious code. In the first one it's hidden on the right, in the second one it comes from an API as text and gets executed with eval().
https://bitbucket.org/bunney-bet-pro/casino/src/4d680db9640bde956bb4d73811e8143ad9cb5a23/server/routes.js#lines-60
https://bitbucket.org/rezoart_workspace/repo_ecommerce/src/3a6b728e110c03c0cea05982558b69cdd33ef4ed/server/controllers/product.js#lines-161Thank you for cleaning this stuff promptly.
Hi @Andrew Katsewich
The abuse mailbox is unable to reply. But reports sent there should still be processed in due time.
That said I raised these repos to my security team and they have confirmed these have been taken-down from our site.
Thanks for reporting them to us.
Andy
Okay, I sent a message on Nov 26 with the first repo, and you saw it was still there today.Thank you!
Another malicious repo found here: https://bitbucket.org/workspace1018/web3game/src/main/
Another one here:Repository: https://bitbucket.org/lyntrex/trading-view1. npm lifecycle hook (package.json line 62) - Executes malicious server code during npm install2. VSCode/Cursor auto-run task (.vscode/tasks.json) - Auto-executes when folder is opened in VSCode/Cursor3. Obfuscated backdoor (.vscode/spellright.dict) - 3,824 bytes of heavily obfuscated JavaScript
It looks like you're new here. Sign in or register to get started.