It seems there is a spike in malicious repositories being uploaded to bitbucket servers. I wish to add another to the list.Repository: https://bitbucket.org/lyntrex/trading-view1. npm lifecycle hook (package.json line 62) - Executes malicious server code during npm install2. VSCode/Cursor auto-run task (.vscode/tasks.json) - Auto-executes when folder is opened in VSCode/Cursor3. Obfuscated backdoor (.vscode/spellright.dict) - 3,824 bytes of heavily obfuscated JavaScript
Hi @Michael Collins
Thanks for raising this as a separate question too.
I also reported this one to Atlassian.
Welcome to the community.
Thanks for reporting this to us.
Regards,Mark C
It looks like you're new here. Sign in or register to get started.