https[://]open-vsx[.]org/extension/micnil/vscode-checkpoints
In my old vscode install I have micnil/vscode-checkpoints installed.
The namespace got claimed by a malicious extension that has no legitimate purpose.
Cursor decided it looked all good and installed the vsx version.
after deobfuscation with jsdfe: JavaScript Deobfuscator Full of Excuses and llm assistance, it’s clear it does at least do data exfil to webhook.site.
I reported this to webhook.site and vsx, as well as the original creator of the extension.
How did this pass the scanning cursor does? obfuscated code and a new github account are dead giveaways no?
I am deeply disappointed. Since I cannot 100% know what got compromised, I have to wipe my disk and change 1000 passwords.
Steps to Reproduce
-have the extension installed in vscode
-open cursor with the setting to transfer vscode extensions enabled
EDIT: the extension has been removed after hundreds of installs.
here is the downloaded package (password: maliciousvscodeextensioninside )
For AI issues: which model did you use?
Model name (e.g., Sonnet 4, Tab…)
For AI issues: add Request ID with privacy disabled
Request ID: f9a7046a-279b-47e5-ab48-6e8dc12daba1
For Background Agent issues, also post the ID: bc-…
Additional Information
Add any other context about the problem here.
Does this stop you from using Cursor?
Yes - Cursor is unusable
Sometimes - I can sometimes use Cursor
No - Cursor works, but with this issue
The more details you provide, the easier it is for us to reproduce and fix the issue. Thanks!