news.volyx.in

Snyk security researcher deploys malicious NPM packages targeting cursor.com (sourcecodered.com)

574 points by arkadiyt · 568 days ago · 312 comments on HN

Article summary

A security researcher discovered malicious NPM packages targeting cursor.com, which were deployed by a user with a Snyk email address. The packages collect system data and send it to an attacker-controlled web service. Snyk is a company that specializes in security and was founded by ex-IDF Unit 8200 soldiers. The researcher believes the packages were likely part of a security test, but notes that using public resources for such tests is not appropriate.

Main themes

  • Security testing
  • NPM package vulnerabilities
  • Supply chain attacks
  • Company responsibility
  • National security concerns
  • Ethics of security research

What commenters say

  • Snyk's actions, whether intentional or not, demonstrate a lack of responsibility and potentially compromised security practices.
  • The use of public resources for security testing is unacceptable and can put others at risk.
  • The fact that Snyk was founded by ex-IDF Unit 8200 soldiers raises concerns about potential ties to the Israeli government and its intelligence agencies.
  • Security researchers should be allowed to test vulnerabilities in a controlled environment, but not on public platforms without permission.
  • The incident highlights the need for clearer guidelines and regulations on security testing and responsible disclosure.
  • The criticism of Snyk is unfair, as the company is likely trying to protect against supply chain attacks and may have been testing a hypothetical scenario.
  • The involvement of former military personnel in the tech industry raises questions about the potential for state-sponsored espionage and surveillance.
  • The incident is a reminder that companies must prioritize transparency and accountability in their security practices to maintain trust with their customers and the public.