Goal is to steal Tea tokens by inflating package downloads, possibly for profit when the system can be monetized.
A new proof-of-concept attack shows that malicious Model Context Protocol servers can inject JavaScript into Cursor’s browser ...