Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Hackers poison popular Rust crates to steal developers' credentials

Malicious updates turned routine builds into a delivery system for infostealer malware

Hackers poison popular Rust crates to steal developers' credentials

Rust developers' credentials were stolen by hackers who injected malware into widely-used Rust packages, a supply chain attack disclosed this week. The Rust Security Response Team found the malware-laden build script in crate proc-macro1, which downloaded malicious code from a remote server during compilation. This attack affected other popular crates: arrayref, internment, and append-only-vec, all created by the same developer.

The attacker deleted these legitimate crates, steering users towards malicious versions. The malicious code targeted developers' operating systems and processors, downloading unique payloads for Linux, Windows, Intel Macs, and Apple Silicon Macs. It also aimed to compromise Chromium-based browsers and cryptocurrency wallets, establishing persistence for future attacks.

The Rust team, Nextron Systems, and security firm Aikido are investigating the extent of the damage and compromised systems.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Friday 21 August →