Malicious arrayref 0.3.10 was downloaded 2,285 times from crates.io in the 86 minutes before Rust's security response team deleted it on August 20. Lockfiles still pinned to 0.3.9 kept most builds away from its unsandboxed build-script payload.
Reality
- Evidence62
- Adoption18
- Hype gap+8
- Incentives
- Insufficient
- Confidence60
OX Security found 101 npm forks of the Baileys WhatsApp library, downloaded 490,000 times, that add developers' accounts to groups without consent. About a quarter of those downloads came in the last 30 days, so the campaign is still reaching new installs.
Reality
- Evidence50
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.
Publishers:blog.rust-lang.org · dev.to · lwn.net · research.jfrog.com · runtimewire.com · rustsec.org · socket.dev Perspective Coverage
7 publishers
- Builder
- Builder 38%
- Operator
- Operator 54%
- Investor
- Investor 8%
Reality
- Evidence86
- Adoption15
- Hype gap+35
- Incentives60
- Confidence82
Three versions of MemTensor's MemOS Cloud plugin on npm and MemoryOS 2.0.34 on PyPI launch a Go stealer called sckit that reads the host environment and the user's prompt text, and the npm versions are still installable.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence64
Aikido found the Graphalgo implant inside two Terraform providers and two Go modules. The Go build polls a hard-coded testnet contract every three seconds and keeps a Slack bot channel open as its second route.
Reality
- Evidence66
- Adoption21
- Hype gap+14
- Incentives72
- Confidence58
Aikido found the Graphalgo campaign's Go port inside two Terraform providers, one of them a typosquat of kreuzwerker/docker. The payload decrypts only when containerName and networkID hash to a hardcoded SHA256.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence61
CISA says a trojanized extension version, 18.95.0, reached a GitHub employee's machine without anyone installing it, and internal repositories left from there. CVE-2026-48027 is now in the KEV catalog.
Reality
- Evidence76
- Adoption58
- Hype gap−8
- Incentives24
- Confidence74