Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removed packages are still listed on packagecontrol.io #154

Open
deathaxe opened this issue Jul 23, 2022 · 3 comments
Open

Removed packages are still listed on packagecontrol.io #154

deathaxe opened this issue Jul 23, 2022 · 3 comments

Comments

@deathaxe
Copy link

Packages like One Dark Color Scheme have been removed from registry years ago. They are still listed at packagecontrol.io however.

grafik

@markarce
Copy link

I was recently browsing for packages and found what appears to be a removed package with a malicious / naughty link.
https://packagecontrol.io/packages/Makefile%20Improved
The homepage and author links include the following url: quelltexter (DOT) org
The url redirects to a porn thumbnail page of some kind. One can imagine why this might be a problem while browsing packages at say, the office.

Abandoned / deleted packages can still show up in search (on packagecontrol.io and in the packagecontrol plugin) and cause problems when, for example, domains change hands and the new owner does something else (as in this case).

@deathaxe
Copy link
Author

I am slightly concerned about "Makefile Improved" as the related repository has been removed in Aug 2020. (wbond/package_control_channel@ee49390)

As all readme links of all packages of klorenz point to the same malicious URL, it appears packagecontrol.io may have been compromized.

@markarce
Copy link

I think it’s more likely that klorenz registered the domain originally and let the domain expire, and the expired domain was then registered by the malicious actor who set it to redirect to where it does now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants