Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Scam Alert

Arrafi Ahmed
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 9, 2024

Scammer named "kerry_wallac" contacted me on fiverr, and shared this malicious project, which has some encrypted code to steal personal info from device:

https://bitbucket.org/madyson99/web3_demo

details about similar scam: https://shorturl.at/6Ns3t

9 answers

1 accepted

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

Post a new question

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 6, 2025

Hi everyone,

Thank you all for the previous reports of malicious repos on Bitbucket Cloud.  We have recently changed our process for reporting on these.   Going forward, please send an email to abuse@atlassian.com in order to report such violations of our terms of service.

 

Someone from our abuse team will review these and respond as needed.

Thanks again,

Andy

1 vote
Arpan Dutta
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 4, 2025

I also have received a shady repo to check out: 

https://bitbucket.org/crypto-oasis-socifi-multi/crypto-oasis-socifi-multi/src/main/


I am pretty sure this is a scam as well, can this be reviewed as well?

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 4, 2025

Thanks for reporting it to us.  The repo has been suspended.

Arpan Dutta
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 4, 2025

Thank you!

 

0 votes
kaptainkool
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 5, 2025

Hi,

Not sure if this repo is also malicious. I am probably too dumb to find anything. Please one of you experts weigh in.

 

URL: https://bitbucket.org/auctionwave_webplatform/auctionwave/src/ 

 

Thanks!

Per Obiora February 6, 2025

I received the same repo a few days ago, in yours the malicious code was removed from the file where i found it last time, but since it's the same code-project, i'd say its better not to not run it..

 

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 6, 2025

That repo has been suspended.

0 votes
Jim Bit
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 4, 2025

From a post job i received this repo: https://bitbucket.org/finance_hub/stake_manager_ui/src/master/  can someone check if this is a scam..

Per Obiora February 5, 2025

Don't run it on your local machine. Just took a look at it, and i'm certain it is a scam designed to steal your information related to your crypto wallets, and in fact even create transaction without your knowledge

Like Jim Bit likes this
Jim Bit
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 5, 2025

Thank you! 

Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 5, 2025

That repo has been suspended.  Thanks for reporting it to us.

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
January 21, 2025

Thanks for reporting it to us, the repo has been suspended.

0 votes
Per Obiora January 21, 2025

Same here.. https://bitbucket.org/auctionwavewebplatform/auctionwave/src/main/

Someone on fiverr asked me to check out his project. Found lot's of obfuscated code in the root tailwind.config.js file. Crazy. Deobfuscated a bunch, and he's been trying to steal crypto wallet keys, login keys from keychain & my browser along with some more information. 

and send it to "http://185.153.182.241:1224/uploads " , "http://185.153.182.241:1224/client/10/100 ", "http://185.153.182.241:1224/pdown " . 

pretty crazy scam that i haven't come across yet... 

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
January 14, 2025

Hi @Samuel 

Thanks for reporting it.  The repo has been taken down.

 

0 votes
Samuel
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 7, 2025

Hi,

 

I think this is the same people, someone contacted me onn fiverr with the username "smith54069" and share a project with the same name in bitbucket. here's  the link to that repository https://bitbucket.org/tommy06151/web_pro/src/master/

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 10, 2024

Hi @Arrafi Ahmed 

Thank you for reporting this repo to us.  Our team has reviewed this repo and taken it down.

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

Post a new question

TAGS
AUG Leaders

Atlassian Community Events