Skip to content

Synchronize repository#250168

Merged
samczsun merged 1 commit into
MetaMask:mainfrom
security-alliance-bot:329ddf48-fe5e-4b89-8ac3-2379849f8cf3
May 24, 2026
Merged

Synchronize repository#250168
samczsun merged 1 commit into
MetaMask:mainfrom
security-alliance-bot:329ddf48-fe5e-4b89-8ac3-2379849f8cf3

Conversation

@security-alliance-bot
Copy link
Copy Markdown
Collaborator

@security-alliance-bot security-alliance-bot commented May 24, 2026

This is an automated pull request to synchronize this repository with the latest configuration


Note

Low Risk
Small denylist edit via automated sync; no application logic or auth changes.

Overview
Automated config sync removes two phishing-style host entries from the repository blocklist in src/config.json: kra42cc-cc.ru and kra45.kra------40--------cc.ru. Neighboring entries (e.g. www--kra45-cc.ru) are unchanged.

Reviewed by Cursor Bugbot for commit f595533. Bugbot is set up for automated code reviews on this repo. Configure here.

@samczsun samczsun added the blocklist addition Issue or PR requesting addition of a domain to the blocklist label May 24, 2026
@samczsun samczsun merged commit 8eba212 into MetaMask:main May 24, 2026
6 checks passed
@security-alliance-bot security-alliance-bot deleted the 329ddf48-fe5e-4b89-8ac3-2379849f8cf3 branch May 24, 2026 15:44
Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

Reviewed by Cursor Bugbot for commit f595533. Configure here.

Comment thread src/config.json
"14coinbase.com",
"camp-network.com",
"krek-en-log.pages.dev",
"kra42cc-cc.ru",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Phishing domains removed from security blocklist

High Severity

Two phishing domains (kra42cc-cc.ru and kra45.kra------40--------cc.ru) were removed from the blacklist. These follow the exact same naming pattern as dozens of other kra42*/kra45* Kraken-impersonation phishing domains that remain blocked (e.g., kra42cc-original.ru, kra45.kra-------40--------cc.ru). Removing them unblocks these phishing sites for Web3 users without apparent justification.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit f595533. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

blocklist addition Issue or PR requesting addition of a domain to the blocklist

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants