-
-
Notifications
You must be signed in to change notification settings - Fork 45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Removed packages are still listed on packagecontrol.io #154
Comments
I was recently browsing for packages and found what appears to be a removed package with a malicious / naughty link. Abandoned / deleted packages can still show up in search (on packagecontrol.io and in the packagecontrol plugin) and cause problems when, for example, domains change hands and the new owner does something else (as in this case). |
I am slightly concerned about "Makefile Improved" as the related repository has been removed in Aug 2020. (wbond/package_control_channel@ee49390) As all readme links of all packages of klorenz point to the same malicious URL, it appears packagecontrol.io may have been compromized. |
I think it’s more likely that klorenz registered the domain originally and let the domain expire, and the expired domain was then registered by the malicious actor who set it to redirect to where it does now. |
Packages like One Dark Color Scheme have been removed from registry years ago. They are still listed at packagecontrol.io however.
The text was updated successfully, but these errors were encountered: