Live data from Hacker News

Snyk security researcher deploys malicious NPM packages targeting cursor.com

sourcecodered.com

71–80 of 331 posts

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#71
post #15

[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…

cursor dev here. reasonable assumptions, but not quite the case. the snyk packages are just the names of our bundled extensions, which we never package nor upload to any registry. (we do it just like how VS Code does it: https://github.com/microsoft/vscode/tree/main/extensions ) we did not hire snyk, but we reached out to them after seeing this and they apologized. we did not get any confirmation of what exactly they…

> "pretty irresponsible"

Wouldn't it be more like "pretty illegal"? They could have simply used body: JSON.stringify("worked"), i.e. not sent target machines’ actual environment variables, including keys.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#72

Earlier quoted context omitted.

The other alternative that those kids were given was to shoot guns or missiles. Are you really comfortable blaming them for the rest of their lives for choosing the option that likely gave them the smallest chance of killing people? Any Israeli citizen in that age bracket today is going to be running a real risk of killing people. They don't have a choice (dodging the draft doesn't count as a choice). If you're going…

Why doesn’t refusing the draft count as a choice?

Because it means a serious risk of the end of your life as you know it. I'm not willing to hold someone else to a standard that I know that I couldn't live up to.

If you truly believe that you'd risk your government's wrath instead of just picking the least dangerous and least likely to kill people branch of your military, then feel free to throw stones. For myself, my plan if the draft were reinstated in the US while I was still of that age was to find out how to join a cyberwarfare division, which would have led me straight to Unit 8200 if I were Israeli.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#73

Earlier quoted context omitted.

cursor dev here. reasonable assumptions, but not quite the case. the snyk packages are just the names of our bundled extensions, which we never package nor upload to any registry. (we do it just like how VS Code does it: https://github.com/microsoft/vscode/tree/main/extensions ) we did not hire snyk, but we reached out to them after seeing this and they apologized. we did not get any confirmation of what exactly they…

[flagged]

I like to call it informal case.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#74

Earlier quoted context omitted.

[flagged]

It’s a techbro thing. Sama does it too

You're writing in rust-inspired English it seems, omitting the punctuation mark at the end of your second sentence so it gets returned.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#76

Earlier quoted context omitted.

It’s a techbro thing. Sama does it too

You're writing in rust-inspired English it seems, omitting the punctuation mark at the end of your second sentence so it gets returned.

it's typesafe and efficient

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#77

I need to get serious about doing all development inside a virtual machine. One project per VM. There are just too many insidious ways in which I can ignorantly slip up such that I compromise my security. My only solace is that I am a nobody without secrets or a fortune to steal. IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.

The real problem is video performance in VMs. It still just...kind of sucks. Running Cinnamon in a VM is just about impossible to get GL acceleration working properly.

nvidia gates it's virtualized GPU offerings behind their enterprise cards, so we're left with ineffective command translation.

IMO: I can tolerate just about every other type of VM overhead, but choppy/unresponsive GUIs have a surprisingly bad ergonomic effect (and somehow leak into the performance of everything else).

If we could get that fixed, at least amongst Linux-on-Linux virtualization, I think virtualizing everything would be a much more tenable option.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#78
post #53

Earlier quoted context omitted.

I have no downside to seeking alternatives. The pager incident ensured that I will always look for non-Israeli tech.

And what does that have to do with Snyk, other than that some of their employees use to work for IDF? I'm a US Navy veteran. Would you also stay away from my employers because they have veterans on staff? Seriously, I get what you're trying to say, but I don't understand the broader point you're trying to make. So Snyk has some ex-IDF employees. Find a high-profile infosec firm that doesn't. They military service the…

Without wanting to take a position here, the GP comment had a specific narrow point.

The claim was that Snyk was founded by Unit 8200 members.

Not that it had a few Israeli veterens, almost all Israeli's serve in the IDF after all.

https://en.wikipedia.org/wiki/Unit_8200

To be fair I have a former Unit 8200 member in my larger extended family who left and has since been vocal in opposition to Netanyahu so membership in an elite Cyber Unit alone doesn't define a person.

That aside, most Governments would keep an eye on a company started by, say, former NSA employees and watch for covert activity under any overt actions.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#79

Earlier quoted context omitted.

Why not? NPM behaves oddly when there is a public package named the same as one on a private repo, in some cases it’ll fetch the public one instead. I believe it’s called package squatting or something. They might have just been showing that this is possible during an assessment. No harm no foul here imo

> They might have just been showing that this is possible during an assessment. No harm no foul here imo You're not supposed to leave public artifacts or test on public services during an assessment. It's possible Cursor asked them to do so, but there's no public indication of this either. That's why I qualified my original comment. However, even if they did ask them to, it's typically not appropriate to use a separa…

if Cursor is secure it shouldn't be a problem for them! (and, according to their comments, it is)

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#80

Earlier quoted context omitted.

Why doesn’t refusing the draft count as a choice?

Because it means a serious risk of the end of your life as you know it. I'm not willing to hold someone else to a standard that I know that I couldn't live up to. If you truly believe that you'd risk your government's wrath instead of just picking the least dangerous and least likely to kill people branch of your military, then feel free to throw stones. For myself, my plan if the draft were reinstated in the US whil…

[deleted]
Post reply on HN