Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Popular Rust Crates Compromised in Build-Time Supply Chain Attack

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,322
Company Posts That Month
22
Language
English
Hacker News Points
9
Post removed?
No
Summary

Security researchers reported a coordinated Rust supply-chain compromise in which malicious releases of the legitimate crates arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 added a dependency on proc-macro1, a typosquatted package resembling proc-macro2. Cargo automatically executed the dependency’s malicious build script during compilation, enabling cross-platform remote code execution on Linux, macOS, and Windows without requiring applications to invoke malicious code directly. The script downloaded and launched platform-specific backdoors that profiled hosts, inventoried Chromium-based browser data, established user-level persistence, communicated with attacker-controlled infrastructure, and could receive commands to download and execute additional code. The Rust Security Response Team removed the affected releases and locked the maintainer account, while indicating the maintainer’s device or publishing credentials may have been compromised rather than the maintainer acting deliberately. Researchers also identified related packages apparently used for staging or testing and warned that developer workstations, CI/CD runners, and release systems that built the affected versions should be treated as potentially compromised, investigated for relevant artifacts and network activity, and have accessible credentials rotated before rebuilding from clean environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 2,244 480 132 -13%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.