“The user who published the NPM package uses a snyk.io email address for the Snyk Security Labs team.”
Packages named after Cursor’s internal modules ran env and sent the output to an outside server. The publisher used a verified Snyk Security Labs address. A security vendor put working exfiltration code on the public npm registry.