Cursor Extension Flaw Exposes Developer API Keys

2026-04-29T20:52:24Zbf08e524814690b2e63acde59e5f5f0cea6c04adb4ecbee78230c4a6aaa01366
CVE-2024-3721ai-securityapi-keysbrowser-extensioncredentialsdata-breachinfostealeriotmalwaremedical-devicesmirainCSCnation-statenorth-koreanpmpasskeysprompt-injectionransomwaresession-tokenssupply-chainwiper

What happened

A broad Infosecurity Magazine roundup reports multiple high‑risk developments: a browser cursor extension flaw that can exfiltrate developer API keys and session tokens; malicious npm supply‑chain packages (including an AI‑assisted commit) targeting developer credentials and crypto wallets and worm‑like propagation; researchers tracking ~2.9 billion compromised credentials with infostealers as a primary vector; a critical Vect 2.0 flaw converting ransomware into an irreversible data‑wiping wiper; and a confirmed Medtronic data breach claimed by ShinyHunters. Other notable items include Mirai‑派

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
bf08e524814690b2e63acde59e5f5f0cea6c04adb4ecbee78230c4a6aaa01366
Enrichment time
2026-04-29T20:52:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cursor Extension Flaw Exposes Developer API Keys · Baitaphish