Security Alert: AI Programming Tool Cursor at Risk of New Virus Hijacking

By: theblockbeats.news|2025/09/05 13:32:25
0
Share
copy

BlockBeats News, September 5th, according to Cointelegraph, cybersecurity firm HiddenLayer reported that the AI programming tool Cursor has a "CopyPasta License Attack" vulnerability. Hackers can hide malicious commands in the LICENSE.txt and README.md files to induce the AI tool to inject the vulnerability into the codebase. This tool is widely adopted by cryptocurrency exchanges like Coinbase.

The attack leverages Markdown comment hiding to inject prompts, causing AI to automatically propagate the malicious payload while editing files. Tests have shown that AI programming tools such as Windsurf, Kiro, and Aider also have the same vulnerability. The malicious code can create backdoors, steal sensitive data, or cripple systems, all while deeply concealing itself to evade detection.

-- Price

--

You may also like

Web3 is dead, Web2+3 should rise

We are not aiming to hold a self-indulgent party for Web3 practitioners, but rather to build a bridge for rational connection between Web2 and Web3.

Stablecoins and Latin American Remittances: The Misunderstood $174 Billion Market

In the Latin American remittance market, the real protagonists have never been the young people speculating on cryptocurrencies, but rather the 50-year-old workers who send money to their mothers every month. They don't care about blockchain; they only care about whether the money has arrived.

The arrival of the Web 3.0 era: A review of Hong Kong court rulings on digital assets

Hong Kong judiciary landmark: The court officially recognizes cryptocurrency as legal property and introduces the "tokenized injunction" to track and freeze involved funds, comprehensively upgrading the protection of digital asset investors.

Track Markets At a Glance: New WEEX Price Widgets for iOS & Android

To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets

The billion-dollar lesson: The focus of DeFi security is shifting from code to operational governance

Warning of nearly $1 billion loss in DeFi: Security pain points have shifted from code vulnerabilities to permissions and operations. Introducing TradFi bank-level risk control and AI defenses is the way to balance openness and security.

A Brief Analysis of Stablecoin Licenses and On-Chain Funding

Hong Kong accelerates the layout of digital finance, providing a panoramic analysis of the evolution of three major on-chain financial forms: central bank digital currency, deposit tokens, and stablecoins, along with future opportunities.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com