No, abuse@atlassian.com does not produce any results and no one replies there.
I have 2 repositories with malicious code. In the first one it's hidden on the right, in the second one it comes from an API as text and gets executed with eval().
https://bitbucket.org/rezoart_workspace/repo_ecommerce/src/3a6b728e110c03c0cea05982558b69cdd33ef4ed/server/controllers/product.js#lines-161
Thank you for cleaning this stuff promptly.
The abuse mailbox is unable to reply. But reports sent there should still be processed in due time.
That said I raised these repos to my security team and they have confirmed these have been taken-down from our site.
Thanks for reporting them to us.
Andy
Okay, I sent a message on Nov 26 with the first repo, and you saw it was still there today.
Thank you!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.