Malicious App Extensions Recommended by Popular AI IDEs
First seen 6 Jan 2026, 16:41 UTC
•
•20
Export
Article Content
Browse articles
A security flaw in AI-powered development environments Cursor, Windsurf, and Google Antigravity has exposed millions of developers to potential malware. These IDEs, which have over a million users combined, were found recommending non-existent extensions, leading to the risk of installing malicious software. All three tools are derived from VSCode and share similar configuration vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Kimsuky Expands AI Capabilities for Cyberattacks
Jscrambler npm Package Compromised in Supply Chain Attack
Cursor IDE Vulnerability Allows RCE via Malicious Git Repositories
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge
Vibe Coding Tools Found to Generate Critical Security Flaws
Critical RCE Vulnerabilities in Cursor IDE Enable Zero-Click Prompt Injection Attacks