Hackers poison popular Rust crates to steal developers' credentials
Malicious updates turned routine builds into a delivery system for infostealer malware
Hackers compromised popular Rust packages, embedding malware into the build scripts of crates proc-macro1, arrayref, internment, and append-only-vec. This malicious supply chain attack, disclosed by the Rust Security Response Team, aimed to infiltrate developers' machines. The attack, triggered by a build script fetching malware from a remote server, was limited in its duration but impacted widely used crates.
The malicious versions were quickly removed from the registry, yet the damage was potentially extensive. Security firm Aikido analyzed the attack, revealing the malware aimed at various operating systems and browser data, including cryptocurrency wallets. The Rust team removed multiple affected crates, urging developers to review their lockfiles and local caches.
The true extent of the attack remains unclear, with details about the compromised maintainer, number of downloads, and systems impacted not disclosed.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.