๐Ÿšจ The Socket Threat Research Team has discovered a set of malicious npm packages targeting macOS developers using the Cursor AI code editor. They steal credentials, disable updates, and add a persistent backdoor to the IDE.

socket.dev/blog/malicious-npm-

0

If you have a fediverse account, you can quote this note from your own instance. Search https://fosstodon.org/users/SocketSecurity/statuses/114469149715948206 on your instance and quote it. (Note that quoting is not supported in Mastodon.)