Live data from Hacker News

Snyk security researcher deploys malicious NPM packages targeting cursor.com

sourcecodered.com

271–280 of 331 posts

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#271
post #208

Earlier quoted context omitted.

> Cursor does not have a bug bounty Shouldn't this alone be considered criminal negligence at this point? Cursor isn't some random open source project. It's a company that has funding, and subscriptions. Hell, I pay Cursor for a monthly subscription. Pretty incredible that they have no bounty program.

The lack of a bug bounty program doesn't prohibit them from rewarding reported vulnerabilities.

do they though?

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#272
post #134

snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649 They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D Their competence isn't as big as their fame, in my opinion. Also one of their sales people insulted me over email, because appar…

That's extremely unfortunate, especially about the "abandoned" labelling. I've been looking to move off GitHub recently as well, it feels like it's got a bit too much control.

Codeberg looks interesting, and there are self-hosted ones like Forejo that also look great if you're okay with the maintenance.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#273

In the Java world, you need to prove ownership of a given namespace (group id), e.g. via a TXT record for that domain. Isn't there a similar concept for NPM? The package is named sn4k-s3c/call-home, how will a victim be tricked into referencing that namespace sn4k-s3c (which I suppose is owned by the attacker, not Cursor)? I feel like I'm missing part of the picture here.

You're not really missing anything so much as adding a misguided assumption of competence to NPM. Npm doesn't really do namespaces. There's just no ownership to prove as most packages are published like "call-home" with no namespace required. This gives exciting opportunities for you to register cal-home to trap users who miss type, or caII-home to innocuously add to your own or open source projects or whatever. Fun…

> Npm doesn't really do namespaces.

Yes it really does. npm has namespaces (called scoped packages) and even explicitly encourages their use for private packages to avoid this sort of attack. From the npm docs: "A variant of this attack is when a public package is registered with the same name of a private package that an organization is using. We strongly encourage using scoped packages to ensure that a private package isn’t being substituted with one from the public registry." [1]

> This gives exciting opportunities for you to register cal-home to trap users who miss type, or caII-home to innocuously add to your own or open source projects or whatever. Fun isn't it?

npm actively blocks typo-squatting attacks during the publishing process: "Attackers may attempt to trick others into installing a malicious package by registering a package with a similar name to a popular package, in hopes that people will mistype or otherwise confuse the two. npm is able to detect typosquat attacks and block the publishing of these packages." [1]

This thread is full of people demonstrating the concept of confirmation bias.

[1] https://docs.npmjs.com/threats-and-mitigations

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#274

Earlier quoted context omitted.

It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…

wouldn't capturing only env names without values be ideal middle ground? look we had access to your Aws tokens, we could take over your account but we didn't steal actual token, we just got proof that we could access it

Yes I agree names only would have been a better approach here.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#275
post #43

Earlier quoted context omitted.

Vagrant’s popularity seems to have died down with Docker containers but it’s by far my favorite way to make dev environments. Several years ago I worked somewhere that prohibited web browsers and development tools on laptops. If you needed to use a browser, you’d have to use one over Citrix. If you needed to code, you’d use a VDI or run the tools in a VM. At the time I thought their approach was clinically insane, bu…

I started using Ansible a few years back to set up VMs (or Raspberry Pis) with a consistent environment. Once I wrapped my head around it, I've found it very nice for any situation where I need to treat systems as livestock rather than pets.

I use Ansible in local only mode to install/configure macOS as a development environment.

Works well with Homebrew, and copies all the config files that devs often don't set up.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#276

Earlier quoted context omitted.

Given the nature of software development and software developers, especially given American companies decide to value shareholder profits over programmer productivity, this might as well be effectively "You don't need to get vaccines, simply don't get sick from other people."

Things like this are suppose to be provenance of an organizations security engineering teams. Helping to ensure you don't ship something like this. It's also hard for them too because no one wants to force developers to re-implement already solved functionality.

I also have never met a security engineer that was eager to do that.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#277
post #235

The only part of the article I disagree with is this line: > But in general, it’s a good idea not to install NPM packages blindly. If you know what to look for, there are definite signals that these packages are dodgy. All of these packages have just two files: package.json and index.js (or main.js). This is one of several flags that you can use to determine if a package is legit or not. This works -- maybe OK for to…

> If you're pulling in a package that has 400 dependencies, how the heck would you even competently check 10% of that surface area?

At my place of work we use this great security too called Snyk. Definitely check it out

/s

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#278
post #248
post #245

Earlier quoted context omitted.

key word: "conscript" if you're born there, you have little choice in the matter.

I've never met an Israeli who wasn't a dual citizen. It's a choice to stay in Israel and fight in the IDF. In fact, the Snyk founder lives in London now: https://uk.linkedin.com/in/guypo

> I've never met an Israeli who wasn't a dual citizen.

Given that unless you are in Israel you're most likely to be meeting Israeli expats or at the very least people who travel, that's hardly surprising and not great evidence for anything.

> In fact, the Snyk founder lives in London now

So you're acknowledging that you're going to hold their country of origin against them even after they've moved. Got it.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#279

Earlier quoted context omitted.

The FSB is no comparison because it's more equivalent to the NSA—it was a career path, not a place to serve out mandatory military service. FSB agents worked there for decades and chose that instead of any number of other things they could have done. Unit 8200 conscripts worked there for at most 2 years 8 months and chose it instead of a different, more gun-blazing branch of the military. Mandatory military service c…

Fear of Israelis, sure. But hatred? Come on. Israel has done a lot in the past year, and is being accused of genocide. The fact that is used a conscript army makes it worse , not better. Also, okay then let's switch it up to the Russian army. Would you use a product with known ties to some electronic warfare russian army unit. Or rather, would you consider any doubts or hesitations over using said product to be "russ…

> The fact that is used a conscript army makes it worse, not better.

I'm not defending the state, I'm defending the individuals who were conscripted.

The entire point of this subthread is that it's heinous to confuse the two.

> Would you use a product with known ties to some electronic warfare russian army unit. Or rather, would you consider any doubts or hesitations over using said product to be "russophobic"?

If I suddenly learned that some founding members of the JetBrains team had previously been conscripted into the Russian army and had served in a cyberwarfare unit, that would change absolutely nothing for me. And yes, I do consider the backlash against JetBrains in the aftermath of the invasion of Ukraine to have been highly rusophobic.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#280
post #235

The only part of the article I disagree with is this line: > But in general, it’s a good idea not to install NPM packages blindly. If you know what to look for, there are definite signals that these packages are dodgy. All of these packages have just two files: package.json and index.js (or main.js). This is one of several flags that you can use to determine if a package is legit or not. This works -- maybe OK for to…

Wait how in the world does a React carousel component have over 400 deps…

Do you mean https://www.npmjs.com/package/carousel-react? By the looks of it, this was published by someone 7 years ago as part of a personal project. Nothing uses it.

Going through that list... they all look like personal projects, with no dependents, and a single release by a single person.

Post reply on HN