A security researcher discovered malicious NPM packages targeting cursor.com, which were deployed by a user with a Snyk email address. The packages collect system data and send it to an attacker-controlled web service. Snyk is a company that specializes in security and was founded by ex-IDF Unit 8200 soldiers. The researcher believes the packages were likely part of a security test, but notes that using public resources for such tests is not appropriate.