Rust Supply Chain Attack: Malicious Crates with 245M Downloads Target Build-Time Execution
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
proc-macro1 is a typosquatted dependency of the legitimate proc-macro2 crate, used in a supply chain attack against Rust crates. Its build script…
arrayref is a widely used Rust crate with over 245 million downloads. A malicious version (0.3.10) was published via a compromised maintainer…
internment is a Rust crate that was compromised in the August 2026 supply chain attack. Version 0.8.7 was published with a dependency…
append-only-vec is a Rust crate that had a malicious version (0.1.9) published during the supply chain attack. The release included a dependency…
proc-macro2 is a ubiquitous Rust crate that was impersonated by the malicious proc-macro1. The typosquatting was used to trick developers into including…
Nextron Systems GmbH's Research Team initially discovered and reported the malicious proc-macro1 crate to the Rust Security Response Team. Their analysis detailed…
msaRAT is a Rust-based remote access trojan attributed to the Chaos ransomware group. It uses a headless browser and WebRTC DataChannels via…
ClientKing is a Rust implant used by Jewelbug that targets Linux servers and routers. It uses five C&C channels, including a DNS…
HelloBackdoor is a Rust-based implant discovered in systems infected by the HelloNet attack. It enables file uploads and downloads to and from…