Interview scam, run the code, etc etc.
https://bitbucket.org/bitgesell_finance/test4
https://bitbucket.org/bitgesell_finance/test4/src/main/backend/src/middleware/errorHandler.js
lines 35+
I received an email with this "home assesment" via LinkedIn from "Stephen Ruck".
https://bitbucket.org/bitgesell-finance-tech/test5/src/master/
It request this endpoint https://api.mocki.io/v2/m7cw5k4n and reads a cookie from there. That cookie holds Javascript code which
Hi Andy,
Thank you for the report, this repository has been disabled.
Should you encounter something similar in the future, please report it following the steps on this page (the email will go directly to the team handling these reports):
Kind regards,
Theodora
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Another instance of the same scam: https://bitbucket.org/echelon_prime/full-stack/src/main/
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Dave Patten
Thanks for reporting this to us. This repo has been removed.
In the future, should you encounter another malicious or suspicious repo, please email https://www.atlassian.com/trust/report-abuse with the details.
This will automatically create a report for our abuse team to process. That team may not reply to all reports, but this is the ideal way to report this to Atlassian.
Thanks
Andy
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi i received a similar repo to work on as an interview round can u verify this ig it added some malware in my system and i tried to remove it
https://bitbucket.org/bitgesell/test6/src/master/
this is the repo and the malicious code is in the error middle ware
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Diksha
Please contact our abuse team at https://www.atlassian.com/trust/report-abuse with the details of the specific repository on Bitbucket. That will flag the repo for review by our anti-abuse team.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.