Live data from Hacker News

Snyk security researcher deploys malicious NPM packages targeting cursor.com

sourcecodered.com

221–230 of 331 posts

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#221
post #113

Earlier quoted context omitted.

Just a reminder that Unit 8200 is staffed mostly by conscripts who are serving out their mandatory military service and chose to accept an invitation to serve in the cyberwarfare arm of the IDF instead of choosing to shoot guns. In other words, it's staffed by Israeli kids who made the choice most of us would have made under the circumstances. It seems a bit unfair to hold that against them more than 10 years later,…

> In other words, it's staffed by Israeli kids who made the choice most of us would have made under the circumstances. It seems a bit unfair to hold that against them more than 10 years later, no? You could say the same about the guy in a call center in India trying to pull a tech support scam on you over the phone. Yes, he's probably making the best choice he can for his own livelihood, probably the same thing you w…

> Just as you have to treat all Chinese companies as under control of the PRC government and all Australian companies as compromised by their security services, you have to treat all Israeli citizens as under the control of the Israeli military

Got it , and are now all American companies suspect because they are managed behind the scenes by Musk and Trump?

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#222
Snyk Research Labs regularly contributes back to the community with testing and research of common software packages. This particular research into Cursor was not intended to be malicious and included Snyk Research Labs and the contact information of the researcher. We were very specifically looking at dependency confusion in some VS Code extensions. The packages would not be installed directly by a developer.

Snyk does follow a responsible disclosure policy and while no one picked this package up, had anyone done so, we would have immediately followed up with them.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#223
post #91

Earlier quoted context omitted.

I started doing development under a separate non-admin user on my MacBook. I switch to another user for personal stuff, or the admin user to install stuff with Homebrew. Doesn't protect from zero days but it's better than nothing.

I toyed around with this a bit, and it feels like it has significant merit. User separation is about the only security boundary built into Linux from the beginning. I was not totally happy with the workflow I adopted, but it is probably going to be less burdensome than the VM approach.

With Fast User Switching on macOS it's pretty convenient too. The difficulty is remembering to switch user when changing contexts. I tried to set a different wallpaper/icon for each user to make it more obvious which user I'm on, but macOS just resets them all to be the same.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#224

Earlier quoted context omitted.

Conspiracies and politics aside, the reasons for the prominence of 8200 are somewhat boring: it's the largest unit in the IDF, in a relatively small country. Teenagers who demonstrate just about any degree of technical savviness get funneled into it for their mandatory service. It's the equivalent of observing that SFBA startups tend to have a lot of Stanford grads at the helm. (I don't have any particular love for S…

> Conspiracies Not when the dissidents put their name to paper. We, veterans of Unit 8200, reserve soldiers both past and present, declare that we refuse to take part in actions against Palestinians and refuse to continue serving as tools in deepening the military control over the Occupied Territories. It is commonly thought that the service in military intelligence is free of moral dilemmas and solely contributes to…

I don’t think this conflicts with what I’ve said. I’m not claiming Unit 8200 is moral or absolved; I’m saying only that you will run into a lot of 8200 veterans if you interact with any Israeli startup, since it’s a massive unit. Assuming that those people don’t have opinions of their own is likely incorrect, as this letter demonstrates.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#225

Earlier quoted context omitted.

It's not white hat because they actively extract data; if it was just to prove it worked they could've done a console.log, cause npm install to fail, or not extract a payload.

The data they extract is nothing sensitive and this way they can see how many hits they get. The more affected the bigger the headline for them.

In what world is "all environment variables" nothing sensitive?

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#226

Hopefully this makes the Cursor team reconsider security (which doesn't seem very good really). Stopped using it for serious stuff after I noticed their LLMs grabs your whole .env files and sends them to their server... even after you add them to their .cursorignore file. Bizarre stuff. Now imagine a bad actor exploiting this... recipe for disaster.

Security often means the opposite of scalability and growth, so why should they? The business goal is to make sure Cursor grows large enough that they have economics of scale to be a viable business. If you want secure LLM you can use Mistral, which comes with all the EU limitations, good and bad.

Mistral (an LLM company) is not really a substitute for cursor (an IDE). Tabby is probably the closest open-source alternative. https://github.com/TabbyML/tabby

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#227
post #167

I need to get serious about doing all development inside a virtual machine. One project per VM. There are just too many insidious ways in which I can ignorantly slip up such that I compromise my security. My only solace is that I am a nobody without secrets or a fortune to steal. IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.

The security, and overall application stability attack vector, is why I now vouch for processes with OS IPC instead of shared libraries, even if it requires more resources. It doesn't fully sort out the trust issue though, even if everything is sandboxed in some fashion.

I know of IPC, but it has never occurred to me to view as an alternative to shared libraries. It's an intriguing viewpoint I'm having trouble wrapping my mind around. Are there battle-tested real-life examples of IPC being used where shared libs could have been used instead?

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#228
post #3

Just a reminder that Snyk was founded by ex-IDF Unit 8200 soldiers. I would not trust them given what we've seen Israel do to supply chains. https://en.wikipedia.org/wiki/Snyk

So every Israeli is now a Mossad agent and every customer is an enemy of Israel like Hezbollah? You won't buy from Snyk because you want to boycott Israel, just own up to it it's a popular position to take.

I’d put Unit 8200 and Mossad in the same basket. I think I made it clear I’m boycotting Israeli products, I’m not hiding that.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#229
post #156
post #3

Just a reminder that Snyk was founded by ex-IDF Unit 8200 soldiers. I would not trust them given what we've seen Israel do to supply chains. https://en.wikipedia.org/wiki/Snyk

That's absurd. If that's your claim, do you know how many of your daily tools and hardware you should also drop?

I’m dropping as many as I can as is my prerogative as a consumer.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#230
post #3

Just a reminder that Snyk was founded by ex-IDF Unit 8200 soldiers. I would not trust them given what we've seen Israel do to supply chains. https://en.wikipedia.org/wiki/Snyk

Just a reminder that Unit 8200 is staffed mostly by conscripts who are serving out their mandatory military service and chose to accept an invitation to serve in the cyberwarfare arm of the IDF instead of choosing to shoot guns. In other words, it's staffed by Israeli kids who made the choice most of us would have made under the circumstances. It seems a bit unfair to hold that against them more than 10 years later,…

I would under no circumstance join the IDF or even live in Israel. They’re not “kids”, they are military personnel.
Post reply on HN