A new proof-of-concept attack shows that malicious Model Context Protocol servers can inject JavaScript into Cursor’s browser ...
Goal is to steal Tea tokens by inflating package downloads, possibly for profit when the system can be monetized.