Rust Supply Chain Attack: Malicious Crates with 245M Downloads Target Build-Time Execution
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
proc-macro1 is a typosquatted dependency of the legitimate proc-macro2 crate, used in a supply chain attack against Rust crates. Its build script…
proc-macro2 is a ubiquitous Rust crate that was impersonated by the malicious proc-macro1. The typosquatting was used to trick developers into including…
Cybersecurity researchers have uncovered a typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The campaign, tracked as StubMaker by OpenSourceMalware,…
StubMaker is a typosquatting campaign targeting RubyGems users with a Windows-based information stealer. It uses malicious gems with extconf.rb hooks to deliver…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
typo-crypto is a malicious npm package designed to impersonate crypto-js, first published in March 2025. It contained a trojanized file (core.js) and…
crypto-js is a legitimate npm package for cryptographic functions. typo-crypto was designed to impersonate crypto-js through typosquatting.
Zoom is a popular videoconferencing platform used for remote meetings and collaboration. It was impersonated by BlueNoroff in phishing campaigns using typosquatted…
Cybersecurity researchers at JFrog have uncovered a sophisticated NuGet typosquatting campaign targeting the popular Newtonsoft.Json library. The malicious package, named "Newtonsoftt.Json.Net," is…