Malicious arrayref 0.3.10 was downloaded 2,285 times from crates.io in the 86 minutes before Rust's security response team deleted it on August 20. Lockfiles still pinned to 0.3.9 kept most builds away from its unsandboxed build-script payload.
Reality
- Evidence62
- Adoption18
- Hype gap+8
- Incentives
- Insufficient
- Confidence60
Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.
Perspective Coverage
6 publishers
- Builder
- Builder 45%
- Operator
- Operator 48%
- Investor
- Investor 7%
Reality
- Evidence80
- Adoption30
- Hype gap+25
- Incentives55
- Confidence75
The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.
Publishers:blog.rust-lang.org · dev.to · lwn.net · research.jfrog.com · runtimewire.com · rustsec.org · socket.dev Perspective Coverage
7 publishers
- Builder
- Builder 38%
- Operator
- Operator 54%
- Investor
- Investor 8%
Reality
- Evidence86
- Adoption15
- Hype gap+35
- Incentives60
- Confidence82
The Rust Project's crates.io team says attackers posing as recruiters are luring team members and popular crate owners onto video calls that end in a pasted command. In August, one hijacked account shipped malicious crates.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives40
- Confidence70
A developer checked npm, PyPI and crates.io for machine-readable funding data using nothing but their public APIs. npm has a declared field whose value arrives in three shapes, PyPI has hand-typed labels, and the sparse index has neither.
Reality
- Evidence58
- Adoption35
- Hype gap−12
- Incentives30
- Confidence55
The experimental Rust crate keeps tenant_id out of the tool schema and compares an authenticated actor's tenant against ownership that the server resolved itself, allowing the call only when the two values match.
Reality
- Evidence45
- Adoption8
- Hype gap−10
- Incentives30
- Confidence55
An auditor of abandoned crates.io packages rewrote crc32 from the zlib source, added slicing-by-16 and Python bindings, and shipped the result as crc32-v2. Projects that list crc32 still compile the 2015 code.
Reality
- Evidence42
- Adoption10
- Hype gap+35
- Incentives75
- Confidence45
The author of laravel-rest pointed one Eloquent-style client at 62 public APIs across 470 unmocked scenarios and published the wire logs for three of them. Where the rows and the page total live is declared per API.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+16
- Incentives74
- Confidence58
A dev.to writeup credits OpenAI's crawler traffic with surfacing a cache-key collision in RubyGems' CDN that served gemspecs under the wrong package names. For npm shops, the lockfile hash covers the tarball; the lookup that chose it is a separate problem.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+40
- Incentives40
- Confidence35
Attestation proves a package came out of the pipeline it names. When the pipeline is the thing that was owned, the seal still verifies, and a gate that only checks origin passes all 84 versions pushed on May 11.
Reality
- Evidence45
- Adoption45
- Hype gap+12
- Incentives30
- Confidence50
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
Wiz says a compile-time payload reached builds through a typosquatted dependency, and the attacker yanked every clean arrayref release so the responsible fix resolved to the poisoned one.
Reality
- Evidence66
- Adoption74
- Hype gap+12
- Incentives62
- Confidence58
Wiz says the crates.io compromise executed at build time, so reviewing the library source would have caught nothing. Cargo did the rest.
Reality
- Evidence46
- Adoption71
- Hype gap+22
- Incentives68
- Confidence48
Compiling any project that resolved the poisoned crate on August 20 was enough to run a credential stealer. Wiz links the infrastructure to DPRK-attributed campaigns.
Reality
- Evidence48
- Adoption61
- Hype gap+17
- Incentives63
- Confidence52
SecretSpec's dotenv-ng 1.0 makes dollar signs literal after dotenvy silently dropped parts of a bcrypt hash. The damage surfaced as an authentication failure, far from the parser that caused it.
Reality
- Evidence58
- Adoption14
- Hype gap+16
- Incentives68
- Confidence52