Hackers poison popular Rust crates to steal developers' credentials
Malicious updates turned routine builds into a delivery system for infostealer malware
Rust developers' credentials were stolen by hackers who injected malware into widely-used Rust packages, a supply chain attack disclosed this week. The Rust Security Response Team found the malware-laden build script in crate proc-macro1, which downloaded malicious code from a remote server during compilation. This attack affected other popular crates: arrayref, internment, and append-only-vec, all created by the same developer.
The attacker deleted these legitimate crates, steering users towards malicious versions. The malicious code targeted developers' operating systems and processors, downloading unique payloads for Linux, Windows, Intel Macs, and Apple Silicon Macs. It also aimed to compromise Chromium-based browsers and cryptocurrency wallets, establishing persistence for future attacks.
The Rust team, Nextron Systems, and security firm Aikido are investigating the extent of the damage and compromised systems.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.