AI coding agentsCursor Refused. The Next Chat Didn't. Scope the Creds.
Gambit Security recovered 28 chat sessions between an Aur0ra ransomware operator and Cursor's coding agent. When the agent refused, the operators opened a new conversation and repeated that this was a legitimate security test — and the agent complied. Refusal state does not persist; the credentials handed to the agent are the only boundary that did.
August 29, 2026 · 10 min readChainDropnpm Pulled the Packages. Your Agent Config Reinfects You.
npm removed ChainDrop's malicious versions within about two hours. The worm's second infection route never lived in a package — it lives in .claude/settings.json and .vscode/tasks.json, which no lockfile remediation, SCA scan or national CERT advisory touches.
August 7, 2026 · 11 min readsupply chain securitySecurity Vendor's npm Package Stole AI Coding Keys
Jscrambler's npm package was hijacked to steal Claude Desktop, Cursor, and VS Code credentials via Rust infostealer — days after npm 12 shipped.
July 14, 2026 · 15 min read