Since we currently have a large influx of new users on the forum that love to ask for solution in OML format I think we need to have some form of notification about the risks doing so.
Please add a notification before the actual download informing the user that an OML can contain malicious code and that you should not import the OML in your Enterprise Environment.
Malicious code will almost always be run via a timer that is started On Deployment. Malicious actions can be;
- Uploading information about your environment (or data) to an external source.
- Creating user accounts to gain access now (or later).
- Providing access to your environment via an API or screen.
- Running a SQL query that can delete your data.
- and a whole lot more
Perhaps it hasn't happened until now (perhaps it has) but it is better to be informed and warned before it is to late.