What is this trojan?

Where does the bug appear (feature/product)?

Cursor CLI

Describe the Bug

A trojan appears to be activated by Cursor

Steps to Reproduce

Appeared while I was using Cursor in VS Code

Expected Behavior

I would like a way to understand what really happened.

Screenshots / Screen Recordings

Operating System

Windows 10/11

Version Information

About Cursor CLI

CLI Version 2026.08.11-e8db854
Model Auto
Subscription Tier Pro
OS win32 (x64)
Terminal vscode
Shell cmd

Does this stop you from using Cursor

No - Cursor works, but with this issue

Hey, thanks for the report, and sorry for the scare. I can see an antivirus detection in your screenshot, we’ll look into it.

This is most likely a false positive. Cursor CLI on Windows updates itself in the background. It downloads and runs its installer script via PowerShell. Some antivirus tools, including Windows Defender’s ML heuristics, flag this “download and execute” pattern because real malware often uses similar techniques. Detections ending in !ml are heuristic guesses, not confirmed signature matches. We’ve seen a few reports like this, here’s a similar thread: Cursor CLI installation gets blocked by Windows Defender

To confirm it’s the same thing, could you share the exact detection name and the file path Defender flagged. You can find both in Windows Security → Virus & threat protection → Protection history.

If the flagged item is in the cursor-agent folder, or it’s a PowerShell command that links to cursor.com, you can safely restore it from quarantine and run Windows Update to refresh Defender definitions. It also helps to submit it as a false positive to Microsoft via their submission portal so they can fix it faster on the vendor side.

If the flagged file is somewhere not related to Cursor, please treat the warning seriously and tell us what it shows.