Skip to content

company

SafeDep

Vendor reporting the concurrent npm campaigns, including 21 packages squatting CLI binary names from Google's scoped packages and malicious Baileys forks.

Known aliases

  • SafeDep

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Cargo's own yank warning steered builds to the poisoned arrayref 0.3.10

Malicious arrayref 0.3.10 was downloaded 2,285 times from crates.io in the 86 minutes before Rust's security response team deleted it on August 20. Lockfiles still pinned to 0.3.9 kept most builds away from its unsandboxed build-script payload.

Publishers:dev.to

Reality

Evidence62
Adoption18
Hype gap+8
Incentives
Insufficient
Confidence60
build6 publishers

cargo build stopped being a safe verb: arrayref 0.3.10 ran a payload at compile time

The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.

Publishers:blog.rust-lang.orgdev.tolwn.netresearch.jfrog.comruntimewire.comrustsec.orgsocket.dev

Perspective Coverage

7 publishers
Builder
Builder 38%
Operator
Operator 54%
Investor
Investor 8%

Reality

Evidence86
Adoption15
Hype gap+35
Incentives60
Confidence82