Malicious arrayref 0.3.10 was downloaded 2,285 times from crates.io in the 86 minutes before Rust's security response team deleted it on August 20. Lockfiles still pinned to 0.3.9 kept most builds away from its unsandboxed build-script payload.
Reality
- Evidence62
- Adoption18
- Hype gap+8
- Incentives
- Insufficient
- Confidence60
USENIX Security 2025 researchers found 19.7% of packages suggested by 16 LLMs were fake, and 43% of those names recurred on every re-run. Names that repeat can be registered ahead of time, so a team has to vet a suggested dependency before installing it, even when the install succeeds.
Reality
- Evidence58
- Adoption20
- Hype gap+25
- Incentives
- Insufficient
- Confidence50
OpenSourceMalware flagged the campaign on August 15, 2026. The install hook fakes a clean native build while pulling a Windows stealer that goes after browser credentials and crypto wallets.
Publishers:opensourcemalware.com · thehackernews.com Reality
- Evidence72
- Adoption15
- Hype gap+10
- Incentives40
- Confidence70
Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.
Perspective Coverage
6 publishers
- Builder
- Builder 45%
- Operator
- Operator 48%
- Investor
- Investor 7%
Reality
- Evidence80
- Adoption30
- Hype gap+25
- Incentives55
- Confidence75
The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.
Publishers:blog.rust-lang.org · dev.to · lwn.net · research.jfrog.com · runtimewire.com · rustsec.org · socket.dev Perspective Coverage
7 publishers
- Builder
- Builder 38%
- Operator
- Operator 54%
- Investor
- Investor 8%
Reality
- Evidence86
- Adoption15
- Hype gap+35
- Incentives60
- Confidence82
Aikido found the Graphalgo campaign's Go port inside two Terraform providers, one of them a typosquat of kreuzwerker/docker. The payload decrypts only when containerName and networkID hash to a hardcoded SHA256.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence61
Volexity dates UTA0565's exploitation to September 3 and 4, five to six days before it first reported the chain publicly, delivered from typosquats of China Digital Times and the Center for American Progress and ending in a new implant it calls CLEANGULP.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives52
- Confidence64