Website Security Incident

Incident Report for biteship

Resolved

Security Notice — September 16, 2026. Between 02:55 and 08:40 WIB, an unauthorized script was injected into our websites (biteship.com). The script has been removed and have been verified clean.

This script was only active for visitors using Windows computers. It sent visitors' IP address, browser type, pages visited, and approximate location to an unknown third party, and displayed a fake "verify you're not a robot" prompt asking visitors to copy and paste a command into Windows Terminal.

If you saw this prompt and ran the command, please treat that computer as compromised: disconnect it from the network, run a full antivirus scan, and change your passwords from a different device — prioritizing email, banking, and Biteship accounts. If you did not run it, no action is needed.

We apologize for this incident. We are reviewing our security measures to prevent similar incidents in the future.
Posted Sep 16, 2026 - 08:45 WIB