← Snyk

2025 Snyk — NPM packages correlated with Snyk Research sparked dependency-confusion controversy; vendor cited research intent

2025 Unknown records affected Share on X

Data compromised

Potential developer environment or secret material if packages executed (per researcher claims summarized by press—not uniformly confirmed).

Technical writeup

The Register reported that NPM packages naming Cursor-related extension identifiers were removed after researcher allegations of data-harvesting behavior if installed; Cursor’s co-founder posted that Snyk apologized. Snyk’s CTO statement characterized the activity as research into dependency confusion in VS Code extension contexts rather than malicious intent.

Root cause

Publication of test/research packages on the public NPM registry without fully preventing mistaken installs (per vendor statement and press dispute).

References