IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.
Snyk security researcher deploys malicious NPM packages targeting cursor.com
21–30 of 331 posts
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#22Earlier quoted context omitted.
This is a tiresome motte-and-bailey argument. You are trying to conflate the OP comment with something it's not (base antisemitism). Just like companies founded by say former operatives of the CIA, NSA, MI6, etc. would (and maybe should?) be viewed with skepticism, so too are companies founded by former members of Unit 8200. Mentioning that Israel's military (like many others) has engaged in some less than ethical be…
Israel has mandatory military service. If anyone who has ever served in the IDF is tarnished and has that part of their life periodically dragged out as evidence that they may be untrustworthy, you're saying that the entire Jewish population of the state of Israel needs to have a giant asterisk attached to them reminding everyone that they were in the IDF. That may not be strictly antisemitic—maybe you're totally fin…
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#23Earlier quoted context omitted.
Israel has mandatory military service. If anyone who has ever served in the IDF is tarnished and has that part of their life periodically dragged out as evidence that they may be untrustworthy, you're saying that the entire Jewish population of the state of Israel needs to have a giant asterisk attached to them reminding everyone that they were in the IDF. That may not be strictly antisemitic—maybe you're totally fin…
I don't understand the purpose of creating ambiguity by confusing mandatory military service and intelligence corp that operates under secrecy. Original post getting flagged is not a great sight either.
What exactly am I confusing by pointing that out?
Were you under the impression that this unit was something like the NSA, staffed with people who chose to spy on people as a career? Because it's not. It's staffed by kids who are very good with computers and who—when given a choice between covert intelligence and a branch that actively shoots guns at people—chose the intelligence arm. Which would you have chosen?
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#24[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…
They could have demonstrated the POC without sending data about the installing host, including all your environment variables, upstream. That seems like crossing the line
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#25[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…
we did not hire snyk, but we reached out to them after seeing this and they apologized. we did not get any confirmation of what exactly they were trying to do here (but i think your explanation that someone there suspected a dependency confusion vulnerability is plausible. though it's pretty irresponsible imo to do that on public npm and actually sending up the env variables)
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#26Earlier quoted context omitted.
I don't understand the purpose of creating ambiguity by confusing mandatory military service and intelligence corp that operates under secrecy. Original post getting flagged is not a great sight either.
IDF Unit 8200 consists of thousands of conscripts serving their mandatory military service. If I were in Israel subject to conscription, I would absolutely have attempted to position myself into that unit for my mandatory service, as would most here. Beats the infantry. What exactly am I confusing by pointing that out? Were you under the impression that this unit was something like the NSA, staffed with people who ch…
Just months ago, some of those "kids who are very good with computers" caused compromised pagers to explode, with no knowledge of who would be near them. Civilians, including children, died as a result. It is right to think people who are "good with computers" in this way might not have the best intentions in their other applications of computers.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#27Wouldn't a lot of small packages consist of just these two files, meaning seeing just these two files in a package may raise an eyebrow but hardly be a smoking gun?
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#28Earlier quoted context omitted.
They just recently snuck bombs into a supply chain and then remotely detonated them in positions where the caused civilian injuries. I would assume the comment has nothing to do with religion/race, and everything to do with the actions taken. Even for someone that is a supporter of that government, it's hard to deny they've taken some actions that are unsupportable.
Who is "they"? Are we talking about Snyk? IDF Unit 8200? The IDF as a whole? The state of Israel? Jews in general? The reason why OP's comment feels like a racist dog whistle is because it's an enormous and dangerous generalization that seems to encompass an entire country. Israel has mandatory military service—if everyone who's ever served in the IDF is untrustworthy because they served in the IDF then you're by def…
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#29Earlier quoted context omitted.
IDF Unit 8200 consists of thousands of conscripts serving their mandatory military service. If I were in Israel subject to conscription, I would absolutely have attempted to position myself into that unit for my mandatory service, as would most here. Beats the infantry. What exactly am I confusing by pointing that out? Were you under the impression that this unit was something like the NSA, staffed with people who ch…
https://www.timesofisrael.com/hezbollah-pager-explosions-put... Just months ago, some of those "kids who are very good with computers" caused compromised pagers to explode, with no knowledge of who would be near them. Civilians, including children, died as a result. It is right to think people who are "good with computers" in this way might not have the best intentions in their other applications of computers.
Any Israeli citizen in that age bracket today is going to be running a real risk of killing people. They don't have a choice (dodging the draft doesn't count as a choice). If you're going to hold that over for them for the rest of their lives I don't know how that's distinct from racism (or countryism if you prefer).
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#30[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…
Allowing someone full access to the contents of your environment (i.e. output of env command) is a big deal to most, I suspect.