Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Backdooring the IDE: Malicious npm Packages Hijack Cursor Ed...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
957
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Malicious npm packages named sw-cur, sw-cur1, and aiide-cur have been identified by the Socket Threat Research Team as targeting macOS users of the Cursor AI code editor, posing as legitimate developer tools to exploit the IDE's trust, steal credentials, and establish a persistent backdoor. These packages have been downloaded over 3,200 times and function by overwriting critical files like Cursor’s main.js, disabling auto-updates, and using encrypted payloads to maintain unauthorized access. The attack exploits developers’ interest in cheaper access to Cursor’s AI features by offering "the cheapest Cursor API," thereby luring users into downloading the malicious packages. This poses significant risks, including credential theft, code exfiltration, and potential introduction of additional malware, compromising both individual developers and enterprise environments. Organizations are advised to restore Cursor from verified installers, rotate compromised credentials, and audit source control and build artifacts to mitigate the threat.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.