The coordinated campaign has so far published as many as 46,484 packages, according to SourceCodeRED security researcher Paul ...
A new proof-of-concept attack shows that malicious Model Context Protocol servers can inject JavaScript into Cursor’s browser ...