Scenarios#
Update: Mauro Soria pointed out that this attack vector can be easily adapted for phishing scenarios:
Share a GitHub repo
Give some instructions to access the attacker server with Cursor or VS Code.
POC#
References#
“Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development