Skip to content

Topic

Package Typosquatting

A supply-chain attack technique: malicious packages published under names mimicking, misspelling, or reusing abandoned names of popular dependencies.

Current stories

build1 publisher

Cargo's own yank warning steered builds to the poisoned arrayref 0.3.10

Malicious arrayref 0.3.10 was downloaded 2,285 times from crates.io in the 86 minutes before Rust's security response team deleted it on August 20. Lockfiles still pinned to 0.3.9 kept most builds away from its unsandboxed build-script payload.

Publishers:dev.to

Reality

Evidence62
Adoption18
Hype gap+8
Incentives
Insufficient
Confidence60
security6 publishers

A backdoor that fires at cargo build: the arrayref poisoning puts your build boxes in scope

Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.

Perspective Coverage

6 publishers
Builder
Builder 45%
Operator
Operator 48%
Investor
Investor 7%

Reality

Evidence80
Adoption30
Hype gap+25
Incentives55
Confidence75
build6 publishers

cargo build stopped being a safe verb: arrayref 0.3.10 ran a payload at compile time

The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.

Publishers:blog.rust-lang.orgdev.tolwn.netresearch.jfrog.comruntimewire.comrustsec.orgsocket.dev

Perspective Coverage

7 publishers
Builder
Builder 38%
Operator
Operator 54%
Investor
Investor 8%

Reality

Evidence86
Adoption15
Hype gap+35
Incentives60
Confidence82