A popular Python library just became a backdoor to your entire machine
…It was first spotted by FutureSearch when an MCP plugin running inside Cursor pulled the package as a transitive dependency , and the machine ran out of RAM due to an exponential fork…