Content
@
https://warpcast.com/~/channel/eth-security
0 reply
0 recast
0 reaction
Officer’s Notes
@officercia
Researchers from kaspersky Lab have shared the results of their investigation into an incident involving a blockchain developer who fell victim to a scam. It turned out that a fake extension for the Cursor IDE code editor infected devices with remote access tools and info stealers, which led to the theft of $500,000 in cryptocurrency from the mentioned developer.
1 reply
3 recasts
4 reactions
Officer’s Notes
@officercia
Cursor AI IDE is an AI-based development environment built on Microsoft’s Visual Studio Code. It includes support for Open VSX, an alternative to the Visual Studio Marketplace, allowing the installation of VSCode-compatible extensions to enhance the software's functionality. Notably, the victim's operating system was installed just a few days before the incident. Only the most essential and popular programs were loaded onto the infected device. However, it was reported that no antivirus software was installed, and free online services were used. After obtaining a disk image of the device and analyzing it, Kaspersky researchers discovered a malicious JavaScript file named extension.js located in the .cursor/extensions directory.
1 reply
0 recast
0 reaction