Security researchers have demonstrated new attack methods targeting AI-powered browsers and integrated development environments (IDEs) by exploiting their integration with external servers and AI sidebars. In one case, a proof-of-concept attack showed that a rogue Model Context Protocol (MCP) server could inject malicious JavaScript into Cursor’s built-in browser, allowing attackers to replace login pages, harvest credentials, and potentially compromise the victim’s workstation by leveraging the IDE’s privileges. The attack leverages the client-server architecture of MCP, which is increasingly used in AI agent workflows, and highlights the risks of using unvetted or custom MCP servers in developer environments.
Separately, researchers have revealed an "AI sidebar spoofing" technique that targets AI browsers such as Comet by Perplexity and Atlas by OpenAI. This attack exploits users’ trust in AI-generated instructions by manipulating the AI sidebar interface, potentially leading to credential theft or other malicious outcomes. Both attack vectors underscore the expanding attack surface introduced by AI integrations in browsers and development tools, and the need for heightened scrutiny of third-party server integrations and user interface trust boundaries in AI-powered applications.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Security researchers from Knostic.ai demonstrated a proof-of-concept attack showing that a malicious Model Context Protocol server can inject JavaScript into Cursor's built-in browser. The attack can replace login pages, steal credentials and cookies, and potentially lead to full workstation compromise because the MCP server inherits the IDE's privileges.
Researchers described a new attack technique called AI sidebar spoofing in which a malicious browser extension injects a fake AI assistant sidebar into AI-powered browsers such as Perplexity Comet and OpenAI Atlas. The method could be used to deliver phishing prompts, malicious links, or device-compromise instructions by abusing user trust in browser-integrated AI.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.