basilio / responsiveCarousel

Simple carousel
MIT License
113 stars 64 forks source link

Embedded malicious code #54

Closed aaron-stripe closed 5 years ago

aaron-stripe commented 5 years ago

Hello,

Just wanted to highlight that on July 13, someone committing as @jakob-everson added malicious code to this repo.

Initial commit is here: https://github.com/basilio/responsiveCarousel/commit/aec0aa71fcdd189e4983c9dedc52e32f2cf4a29f

You can see the malicious code here : https://github.com/basilio/responsiveCarousel/blob/master/responsiveCarousel.js#L1201

I'm reporting this to cdnjs and GitHub. @basilio - can you clean this up?

basilio commented 5 years ago

Thanks @aaron-stripe

aaron-stripe commented 5 years ago

Thanks @basilio. Can you explain why @jakob-everson was given access to the repo? And why they are adding malicious code?