Hi there! Unfortunately with so many plugins with good intentions, there’s bound to be Ne’er-do-wells.
First and foremost, I would file a DMCA notice with the websites owner, as Content Mask explicitly states in it’s terms that a user must have license to use the content that they are embedding.
Secondly, if they are using the ‘iframe’ method, you can prevent your website from being embedded in iframes. Here’s a helpful link on how to do that: https://stackoverflow.com/questions/2896623/how-to-prevent-my-site-page-to-be-loaded-via-3rd-party-site-frame-of-iframe
If they’re using the ‘Download’ method, you can prevent your assets from being hotlinked with some .htaccess rules. Here’s a link on that: https://stackoverflow.com/questions/6691280/how-can-i-prevent-other-sites-from-linking-to-my-javascript-files
My apologies that this is happening, I assure you the plugin’s intentions are good! If you wouldn’t mind, could you privately email your website and the offending website? I’d like to look into this a bit further. You can contact me directly through my website at https://xhynk.com/