Home / Companies / Socket / Blog / Post Details
Content Deep Dive

5 Malicious Rust Crates Posed as Time Utilities to Exfiltrate .env Files

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
1,741
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team discovered a coordinated supply chain attack in the Rust ecosystem involving five malicious crates, including chrono_anchor, which masquerade as time utilities but are designed to steal credentials and secrets from developer environments. These crates were published between late February and early March 2026 and used a consistent method to exfiltrate data to a domain mimicking the legitimate timeapi.io service. The RustSec and GitHub Advisory Database responded by quickly removing most of these crates, though chrono_anchor initially evaded detection due to minor obfuscation techniques. The threat actor employed strategies such as plausible utility framing and naming conventions that blend into the Rust ecosystem to lower suspicion and increase the likelihood of accidental installation. The malicious code specifically targets .env files, which often contain sensitive information like API keys and tokens, making them valuable targets in supply chain attacks. The research team recommends implementing measures such as running security audits and restricting network access during builds to prevent such attacks in the future.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 6 1,488 268 99 +7%
MCP 1 4,488 443 150 +34%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.