Live data from Hacker News

Snyk security researcher deploys malicious NPM packages targeting cursor.com

sourcecodered.com

191–200 of 331 posts

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#191
post #134

snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649 They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D Their competence isn't as big as their fame, in my opinion. Also one of their sales people insulted me over email, because appar…

"insulted me over email" - whoa, that's wild, do you still have the email? would be fun to see it :D

I get surprisingly many cold emails these days with a passive aggressive “shall we schedule a call, or are you a bad person who doesn’t give a shit about security?” approach.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#192
post #179

Earlier quoted context omitted.

Could you please explain a little more. I can use such practice in my dev workflow.

Sure. They don't include "node_modules" directory in their .gitignore file. So any third party code changes end up in git commits and are easily visible and reviweable. So running npm update/upgrade includes the code that changed in the dependencies in the commit.

This is an option but that makes it easier to conceal malicious code within node_modules as an internal threat actor or make super sure there's a culture of actually reviewing those changes.

In cases like that it helps to do npm install on the CI and make sure you end up with identical code. Decent trade-off.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#193
post #71

Earlier quoted context omitted.

> "pretty irresponsible" Wouldn't it be more like "pretty illegal"? They could have simply used body: JSON.stringify("worked"), i.e. not sent target machines’ actual environment variables, including keys.

It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…

Cursor does not have a bug bounty though, and its hard to see how this constitutes anything other than a direct attack on them, their users, or both. "The incentive structure made me do it" does not justify acting like a criminal.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#194
post #43

I need to get serious about doing all development inside a virtual machine. One project per VM. There are just too many insidious ways in which I can ignorantly slip up such that I compromise my security. My only solace is that I am a nobody without secrets or a fortune to steal. IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.

Vagrant’s popularity seems to have died down with Docker containers but it’s by far my favorite way to make dev environments. Several years ago I worked somewhere that prohibited web browsers and development tools on laptops. If you needed to use a browser, you’d have to use one over Citrix. If you needed to code, you’d use a VDI or run the tools in a VM. At the time I thought their approach was clinically insane, bu…

I started using Ansible a few years back to set up VMs (or Raspberry Pis) with a consistent environment. Once I wrapped my head around it, I've found it very nice for any situation where I need to treat systems as livestock rather than pets.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#195

Earlier quoted context omitted.

It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…

I wonder how viable it would be to find a public key your target owns and use it to encrypt the data you send back. Then you could prove to them that you exfiltrated real data without exposing it to anyone outside the company. Alternatively, you could hash it and say “Look, it’s a sha of your database password hyphen “yougotpwnd””

HTTPS certificates should already have that public key for you, so it should be trivial.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#196
post #71

Earlier quoted context omitted.

> "pretty irresponsible" Wouldn't it be more like "pretty illegal"? They could have simply used body: JSON.stringify("worked"), i.e. not sent target machines’ actual environment variables, including keys.

It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…

wouldn't capturing only env names without values be ideal middle ground?

look we had access to your Aws tokens, we could take over your account but we didn't steal actual token, we just got proof that we could access it

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#197
post #134

snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649 They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D Their competence isn't as big as their fame, in my opinion. Also one of their sales people insulted me over email, because appar…

I'm sure you can provide the body of the [appropriately redacted] said email?

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#198
post #78

Earlier quoted context omitted.

And what does that have to do with Snyk, other than that some of their employees use to work for IDF? I'm a US Navy veteran. Would you also stay away from my employers because they have veterans on staff? Seriously, I get what you're trying to say, but I don't understand the broader point you're trying to make. So Snyk has some ex-IDF employees. Find a high-profile infosec firm that doesn't. They military service the…

Without wanting to take a position here, the GP comment had a specific narrow point. The claim was that Snyk was founded by Unit 8200 members. Not that it had a few Israeli veterens, almost all Israeli's serve in the IDF after all. https://en.wikipedia.org/wiki/Unit_8200 To be fair I have a former Unit 8200 member in my larger extended family who left and has since been vocal in opposition to Netanyahu so membership…

It would correlate strongly that 8200 alumni end up being educated and working in tech, and likely living in Tel Aviv. This is a group of people who, by and large, are not big fans of the current government.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#199
post #166

"no one can hack us" and then "you can't hack us, how dare you" game, 25 years and more

> "no one can hack us" Did Cursor made claims to this effect and invited public to hack them? Or are you equating someone saying they "take security seriously" to "it's an open season, please attack our systems."?

yes it is, like independent product reviews or crash tests of cars. Anyway Kim Jong Un doesn't care.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#200

Earlier quoted context omitted.

Talent or skills is essential but alone is not enough. while the size and quality of the talent pool helps it is not sufficient to explain the success rate, considering that there are similar or better quality talent pools which are larger in many countries around the world, but they don't have the success rates Israeli startups and 8200 ones specifically have compared to their home market and talent pool size. It is…

> benefits from this effect "Benefits" from whose perspective? For instance, the Brazilians (the State apparatus, specifically) are also benefiting [0], but are their citizens [1]? [0] https://www.jstor.org/stable/48595312 [1] https://idanlandau-com.translate.goog/2016/02/04/technologie...

benefits from the perspective of the startup, i.e. chances of its success or growth.

Who in turn benefits from that in terms wealth, power, influence is whole different topic for which i have no expertise, i was only talking about frequency of successes in startup clusters.

Post reply on HN