Hello,
The following public repository contains malicious code:https://bitbucket.org/ethvault-tech-team/ethvault/src/master/
In file server/controllers/productController.js, the function `getCookie` downloads arbitrary code from:https://api.mocki.io/v2/964ug6uuand executes it locally using `new Function(...)` with `require`.
This is a Remote Code Execution vulnerability that could fully compromise a user’s machine.The repository has been online since July 10, 2025 and is being shared with job candidates as a “technical test”.
Please investigate and take action to remove or restrict this repository.
Hi @Frantz Galinier-Stefani,
Welcome to Atlassian Community!
Please report this to abuse@atlassian.com and they will take action on it. Just note that the team will not reply back.
Ok, thx
Hi @Frantz Galinier-Stefani
Thank you for raising this to our attention. I've just reported this directly to our anti-abuse team and will let you know the outcome.
Cheers!
- Ben (Bitbucket Cloud Support)
I can confirm that the content has been taken down, and the user has been de-activated
It looks like you're new here. Sign in or register to get started.