The Joomla Jumi component is backdoored and apparently sends user passwords to another site.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/82376/joomlajumi-backdoored.txt
Source: https://packetstormsecurity.com/files/82376/Joomla-Jumi-Is-Backdoored.html

