Snyk appears to deploy 'malicious' packages targeting Cursor for unknown reason
ID: 1406da8a-f653-5b54-bb1b-eef87515e6a6
STIX ID: report--1406da8a-f653-5b54-bb1b-eef87515e6a6
Feed Name: The Register (Security)
Threat Score
A researcher found three malicious NPM packages (cursor-retrieval, cursor-always-local, cursor-shadow-workspace) that purportedly collected system and environment data—including credentials, AWS keys, and NPM tokens—and sent it to an attacker-controlled service; metadata reportedly pointed to a Snyk.io email, the packages were removed, Snyk apologized, and Cursor says it did not engage Snyk, leaving attribution and intent unclear.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
