
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
cursor-installer
Advanced tools
Downloads and installs the latest Cursor editor on Linux.
npx cursor-installer@latest
Pass --yes (or -y) to skip all confirmation prompts:
npx cursor-installer@latest --yes
What it does:
.desktop entrycursor shell aliasBusiness logic uses Effect generators (Effect.gen), typed errors (Data.TaggedError), and platform services (FileSystem, HttpClient) accessed from Effect context.
The CLI UI is abstracted behind a CliUI service backed by @clack/prompts. The --yes / -y flag swaps CliUIInteractive for CliUIAutoAccept (auto-confirms all prompts).
Tests use bun:test with Effect layers for dependency injection. See src/test-helpers.ts for mock factories (createTestFileSystem, createTestHttpClient, createTestCliUI). Tests swap in a mock CliUI layer to avoid interactive prompts.
bun run test:e2e runs the real installer in a Docker container (oven/bun:slim), downloading from cursor.com. Requires Docker. Uses --yes flag for auto-accept.
MIT
FAQs
Utility script to install or update Cursor on Linux
The npm package cursor-installer receives a total of 1 weekly downloads. As such, cursor-installer popularity was classified as not popular.
We found that cursor-installer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.