It's part of the crypto developer scam where the alleged recruiter sends you a repository to install and evaluate. Then drain your wallets, there is obfuscated js either in the code or in a cookie fetch with eval() . It's been like the 5th time in this month so I recognize the scam quick, this is the first one in bitbucket and can't seem to find a way to report it.Here it is:
https://bitbucket.org/mordern/project_a/src/main/
thank you
Hello @Guillermo Bascuñana
Welcome to the Atlassian Community. Thanks for bringing this up, I am raising it internally with our Bitbucket support team.
I can't promise an SLA on this, but they will review it. If you receive an email or you see anything suspicious you can also report it to https://www.atlassian.com/trust/report-abuse
@Guillermo Bascuñana would you be able to provide more information that this code can be a threat? Our team ran some checks and initially couldn't find anything, in order to do a takedown we would need more clear indication that this is indeed malicious.
Thanks
Another similar repository here: https://bitbucket.org/financial-hub/staking-management/src/master/
This repository has been provided to me on Fiverr and is designed in similar fashion as the exploit here:
https://www.reddit.com/r/CryptoCurrency/comments/18sw38l/blockchain_devs_wallet_emptied_in_job_interview/
It's an old crypto dashboard template modified to scan for local crypto wallets and move the funds out.
I've ran it inside the VMWare, but could not identify how exactly this is being executed (Linux might not even be supported), but I assume it is somehow a part of the build / test chain, likely all the malicious logic is in https://bitbucket.org/financial-hub/staking-management/src/master/test.js
@Arya Thanks for reporting it to us. The repo has been suspended.
Another malicious repository relating to a crypto scam from a potential client on UpWork.https://bitbucket.org/chateaux/meme/src/main/
@Thales Santos There is this one as well https://bitbucket.org/alchemer1/tradingview1/src/main/ , same pattern. They ask you to run the code on your local machine and then funds are drained
Thanks Viktor, it looks like the repository has already been deleted or moderated
Hi Shrinath, welcome to the community. I have reported this to the abuse team.
@Shrinath Prabhu The repository has been taken down.
For you and everyone else coming across this thread if this is seen in the future, you can report it directly to https://www.atlassian.com/trust/report-abuse
https://bitbucket.org/saros_tech_blockchain/dex_v2_mvp/src/main/
Hello @Thales Santos ,
Here's another repo with similar symptom: it contains malicious code and they try to convince the victim running locally
https://bitbucket.org/infinixesoft-workspace/freetokenmarket/src/af2a0d33cebc2c42ec193ef42ca640c0d4d383bd/routes/coreRoutes/coreApi.js#lines-21
This line contains some obfuscated code after the comment
@junzhli please report it to https://www.atlassian.com/trust/report-abuse
I got contacted by somebody suspicious that seem to fit the pattern. Haven't delved deep into it but here is the repo Bitbucket suspicious repository.Will share the name used in case someone finds something fishy.
I saw this repo yesterday and it has been discussed on Linked in as a fraud:You can find the MVP v2 project on Bitbucket here:https://bitbucket.org/socifi-cryptooasis-game-v2/socifi-cryptooasis-game-v2/src/main/It's a LInkedIn Solicitation and there is a link discussing it:
https://www.linkedin.com/posts/ihor-antoniuk-pmp%C2%AE-csm-mcp-mcad-mcsd-55077123_hack-threat-trojan-activity-7317866506594193409-IOWE?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABbkGUBVsVmNpMIIewb0wFUf1jpJjmvXmM
Hi @Brian Beveridge
Welcome to the Atlassian Community, and thanks for bringing this up. It seems that the repository has already been taken down.
If you see anything suspicious in the future you can report the repositories to https://www.atlassian.com/trust/report-abuse
It looks like you're new here. Sign in or register to get started.