Live data from Hacker News

Snyk security researcher deploys malicious NPM packages targeting cursor.com

sourcecodered.com

21–30 of 331 posts

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#21
I need to get serious about doing all development inside a virtual machine. One project per VM. There are just too many insidious ways in which I can ignorantly slip up such that I compromise my security. My only solace is that I am a nobody without secrets or a fortune to steal.

IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#22

Earlier quoted context omitted.

This is a tiresome motte-and-bailey argument. You are trying to conflate the OP comment with something it's not (base antisemitism). Just like companies founded by say former operatives of the CIA, NSA, MI6, etc. would (and maybe should?) be viewed with skepticism, so too are companies founded by former members of Unit 8200. Mentioning that Israel's military (like many others) has engaged in some less than ethical be…

Israel has mandatory military service. If anyone who has ever served in the IDF is tarnished and has that part of their life periodically dragged out as evidence that they may be untrustworthy, you're saying that the entire Jewish population of the state of Israel needs to have a giant asterisk attached to them reminding everyone that they were in the IDF. That may not be strictly antisemitic—maybe you're totally fin…

I don't understand the purpose of creating ambiguity by confusing mandatory military service and intelligence corp that operates under secrecy. Original post getting flagged is not a great sight either.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#23

Earlier quoted context omitted.

Israel has mandatory military service. If anyone who has ever served in the IDF is tarnished and has that part of their life periodically dragged out as evidence that they may be untrustworthy, you're saying that the entire Jewish population of the state of Israel needs to have a giant asterisk attached to them reminding everyone that they were in the IDF. That may not be strictly antisemitic—maybe you're totally fin…

I don't understand the purpose of creating ambiguity by confusing mandatory military service and intelligence corp that operates under secrecy. Original post getting flagged is not a great sight either.

IDF Unit 8200 consists of thousands of conscripts serving their mandatory military service. If I were in Israel subject to conscription, I would absolutely have attempted to position myself into that unit for my mandatory service, as would most here. Beats the infantry.

What exactly am I confusing by pointing that out?

Were you under the impression that this unit was something like the NSA, staffed with people who chose to spy on people as a career? Because it's not. It's staffed by kids who are very good with computers and who—when given a choice between covert intelligence and a branch that actively shoots guns at people—chose the intelligence arm. Which would you have chosen?

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#24
post #15

[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…

> If that's the case, then there's not much to see here

They could have demonstrated the POC without sending data about the installing host, including all your environment variables, upstream. That seems like crossing the line

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#25
post #15

[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…

cursor dev here. reasonable assumptions, but not quite the case. the snyk packages are just the names of our bundled extensions, which we never package nor upload to any registry. (we do it just like how VS Code does it: https://github.com/microsoft/vscode/tree/main/extensions)

we did not hire snyk, but we reached out to them after seeing this and they apologized. we did not get any confirmation of what exactly they were trying to do here (but i think your explanation that someone there suspected a dependency confusion vulnerability is plausible. though it's pretty irresponsible imo to do that on public npm and actually sending up the env variables)

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#26

Earlier quoted context omitted.

I don't understand the purpose of creating ambiguity by confusing mandatory military service and intelligence corp that operates under secrecy. Original post getting flagged is not a great sight either.

IDF Unit 8200 consists of thousands of conscripts serving their mandatory military service. If I were in Israel subject to conscription, I would absolutely have attempted to position myself into that unit for my mandatory service, as would most here. Beats the infantry. What exactly am I confusing by pointing that out? Were you under the impression that this unit was something like the NSA, staffed with people who ch…

https://www.timesofisrael.com/hezbollah-pager-explosions-put...

Just months ago, some of those "kids who are very good with computers" caused compromised pagers to explode, with no knowledge of who would be near them. Civilians, including children, died as a result. It is right to think people who are "good with computers" in this way might not have the best intentions in their other applications of computers.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#27
> All of these packages have just two files: package.json and index.js (or main.js). This is one of several flags that you can use to determine if a package is legit or not.

Wouldn't a lot of small packages consist of just these two files, meaning seeing just these two files in a package may raise an eyebrow but hardly be a smoking gun?

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#28
post #9

Earlier quoted context omitted.

They just recently snuck bombs into a supply chain and then remotely detonated them in positions where the caused civilian injuries. I would assume the comment has nothing to do with religion/race, and everything to do with the actions taken. Even for someone that is a supporter of that government, it's hard to deny they've taken some actions that are unsupportable.

Who is "they"? Are we talking about Snyk? IDF Unit 8200? The IDF as a whole? The state of Israel? Jews in general? The reason why OP's comment feels like a racist dog whistle is because it's an enormous and dangerous generalization that seems to encompass an entire country. Israel has mandatory military service—if everyone who's ever served in the IDF is untrustworthy because they served in the IDF then you're by def…

It's not just the IDF, you have a CHOICE to join the spymaster side of it, vs being a regular grunt. That unit is part of Aman, the military version of Mossad.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#29

Earlier quoted context omitted.

IDF Unit 8200 consists of thousands of conscripts serving their mandatory military service. If I were in Israel subject to conscription, I would absolutely have attempted to position myself into that unit for my mandatory service, as would most here. Beats the infantry. What exactly am I confusing by pointing that out? Were you under the impression that this unit was something like the NSA, staffed with people who ch…

https://www.timesofisrael.com/hezbollah-pager-explosions-put... Just months ago, some of those "kids who are very good with computers" caused compromised pagers to explode, with no knowledge of who would be near them. Civilians, including children, died as a result. It is right to think people who are "good with computers" in this way might not have the best intentions in their other applications of computers.

The other alternative that those kids were given was to shoot guns or missiles. Are you really comfortable blaming them for the rest of their lives for choosing the option that likely gave them the smallest chance of killing people?

Any Israeli citizen in that age bracket today is going to be running a real risk of killing people. They don't have a choice (dodging the draft doesn't count as a choice). If you're going to hold that over for them for the rest of their lives I don't know how that's distinct from racism (or countryism if you prefer).

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#30
post #15

[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…

> If that's the case, then there's not much to see here.

Allowing someone full access to the contents of your environment (i.e. output of env command) is a big deal to most, I suspect.

Post reply on HN