Trojan in Cursor

Describe the Bug

PDM:Trojan.Win32.Generic

Steps to Reproduce

Use Kaspersky Free

Screenshots / Screen Recordings

Operating System

Windows 10/11

Current Cursor Version (Menu → About Cursor → Copy)

Version: 1.4.2 (user setup)
VSCode Version: 1.99.3
Commit: 07aa3b4519da4feab4761c58da3eeedd253a1670
Date: 2025-08-06T19:23:39.081Z
Electron: 34.5.1
Chromium: 132.0.6834.210
Node.js: 20.19.0
V8: 13.2.152.41-electron.0
OS: Windows_NT x64 10.0.26100

Additional Information

Cursor is laggy, freeze and crash

Does this stop you from using Cursor

Sometimes - I can sometimes use Cursor

1 Like

Hi @hugohamelcom thank you for the report.

This does look like a generic report without actual malware detection as no specific malware was detected.

I will pass this to the team for a check.

1 Like

Hey, since Cursor has built-in API connections, both outgoing and incoming, the antivirus might consider it a virus. You can add Cursor to the exceptions.

2 Likes

Simple fact : would a hacker, and APT attacker, be stupid enough to call his trojan TROJAN ?

Every day on this forum amaze me even more.

3 Likes

Of course it is a false positive, but the point is for Cursor to be aware and try to avoid being labelled as a trojan when we both know that there is no trojan (at least not voluntarily).

1 Like

Describe the Bug

Kaspersky found trojan in cursor.exe What is this?

Steps to Reproduce

Can you explain this?

Screenshots / Screen Recordings

Operating System

Windows 10/11

Current Cursor Version (Menu → About Cursor → Copy)

Version: 1.4.2 (user setup)
VSCode Version: 1.99.3
Commit: d01860bc5f5a36b62f8a77cd42578126270db340
Date: 2025-08-07T17:16:23.005Z
Electron: 34.5.1
Chromium: 132.0.6834.210
Node.js: 20.19.0
V8: 13.2.152.41-electron.0
OS: Windows_NT x64 10.0.26100

hi @furkancak1r this is a generic message and a false positive, not an actual trojan.

1 Like

This morning I rebooted and Kapersky uninstalled cursor entirely

1 Like

Could you share the elements leading to this deletion ?

Because I’d venture to say Windows using a service to take screenshots every few seconds even if you opt out Recall has not been deactivated.

Also if you happen to use chrome (brave, chromium, edge, ungoogled-chromium, opera), it may be interesting to remember:

  • Google massive data breach of user passwords. If used, and because chromium/electron share a whole range of SHARED uniquely identifiers (ipc-crash-handler, V8, countless others) leaking in realtime metadata, it enables lateral movement spread accross your entire range of electron apps.
  • Pixel - yandex exploit using a frontend - because these apes real engineers consider roughly equal to vibecoders - make frontend code using root privileges with the ability to benefit to any process tied to the node having it - with a known bounceback enabling interception by ‘shadow_root’ - and the browser will consider it ‘null’.

Kapersky will not tell you so I’m gonna even give you the question to ask: ‘if a process is able to autosign legitimate windows certificates, whitelist itself from windows defender and its registry, open autosigned RPC endpoints, and spread, rewrite entire registries to the extent it can even temper safe reboot, would it be the reason you wouldn’t even dare make a press release about it despite alarm bells for more than a year ?”

Think about it, if an update could brick WORLDWIDE windows servers for days and blackout the WORLD airline systems, do you even believe there is a remote chance an antivirus could save you ?

The same happens to me

After following the steps to exclude cursor.exe in kapspersky, it did it again now. as soon as cursor tries to modify a file, kaspersky sees it as a trojan and quarantines the file. It is a false positive, but that doesn’t change the frustration of why this is happening, how to prevent it and why has this just stared after 6 months of using cursor.

Its likely that an heuristics update by Kaspersky is causing it. Could you contact Kaspersky to check this?

1 Like

I am chatting to them. They looking into it.

3 Likes

Great, let me know what they say.

1 Like

ive got an issue that norton thing the actions and files cursor s making is a virus and deleates them makes doing anything impossible is there a fix

Hey, at the moment the solution is simply to add Cursor to your antivirus exceptions.

i have a persistant state level penetration war going on and the cursor method to update the Windows registry was being abused - that cursor registry managemnt method needs to be limited to cursor only - as of right now anything can edit your registry using cursor methods

Its a really big hole in cursor security

Kaspersky is keeping pretty busy monitoring my laptop too

GPT-5 is a fantastic APT hunter destroyer next level defense, better than any antivirus

I have same message from Kaspersky and is trying to remove cursor from PC. When it will be whitelabeled so we can continue doing our things? Thanks

1 Like

Isn’t there some kind of communication channel between the creators of popular software and the creators of popular antiviruses? :thinking: