Summary
Scammers are using VSCode and Cursor exploits to target developers by sending malicious repos under the guise of consulting offers. One user reported being contacted on LinkedIn and asked to open a suspicious repo, which led to immediate suspicion and the scammer disappearing.
AI-assisted summary based on the listed source.
What happened
I encountered this one personally - I was contacted on LinkedIn by someone interested in taking me on as a technical consultant. I agreed to meet with them. At the meeting, they asked me to clone their product's (public?!) repo and open it in Cursor or VSCode. I was immediately suspicious and refused. They...
Why it matters
This highlights a new vector for social engineering attacks leveraging popular AI coding tools, emphasizing the need for caution when opening unknown repositories. Developers should verify the source and contents of code before interacting with it to avoid potential compromise.
Signal Intelligence
Signal Strength 95%
Technical label RISING
Public Interest 55
Category SECURITY
Reader Depth PRACTICAL
Event context 1 source
Signal Strength reflects source quality, relevance, freshness and evidence. Public Interest helps organize discovery; it is not proof of truth.
Public Interest components
Recognizable Entity Score 73
Practical Impact Score 46
Novelty Interest Score 70
Consequence Score 46
Curiosity Score 0
Shareability Score 65
Why this is here
VQV surfaced this signal because it is recent, relevant to AI Coding Tools, connected to Hacker News Newest.