LIVE · cybersecurity feed
Live wire
CVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on HostCISA orders feds to patch actively exploited TrueConf Server flawsCVE-2026-69836 · Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
rusthigh

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Malicious versions of three popular Rust crates were briefly available on crates.io, a package repository, after a compromised maintainer account published them. These releases contained a build script that, during compilation, would download and execute a remote payload. The affected crates were quickly removed, and there is no evidence of widespread use, but developers are advised to check their systems and pin to older, safe versions of the affected libraries.

zeroday.news ·

A supply chain attack targeting the Rust ecosystem was recently reported, involving the brief availability of malicious versions of three popular Rust crates on crates.io, the official package repository. The incident stemmed from a compromised maintainer account, which was used to publish the tainted releases. These malicious versions incorporated a build script designed to download and execute a remote payload during the compilation process.

The mechanism of this attack leverages the build-time capabilities inherent in many software projects. In the Rust ecosystem, `build.rs` scripts are commonly used to perform tasks necessary for compilation, such as generating code, linking to native libraries, or configuring environment variables. In this case, the malicious script was designed to fetch and execute external code, effectively turning the build process into a vector for malware delivery. This type of compromise can be particularly insidious as it targets the development environment itself, potentially affecting any system that compiles the tainted code.

The affected crates were reportedly removed swiftly from crates.io once the issue was identified. While there is no evidence suggesting widespread exploitation or significant impact, the potential for harm from such an attack is considerable. Developers who may have downloaded or built projects incorporating these specific crates during the window of vulnerability are advised to take precautionary measures.

For developers, the primary mitigation strategy involves verifying the integrity of their dependencies. This typically includes reviewing `Cargo.lock` files to ensure that only trusted versions of libraries are being used. Pinning to older, known-safe versions of the affected libraries is a recommended immediate action to prevent accidental re-introduction of the compromised code. Furthermore, developers should consider auditing their build environments for any unauthorized network connections or executed processes that may have resulted from the malicious build script.

This incident underscores the persistent threat of supply chain attacks in modern software development. Attackers increasingly target package repositories and developer accounts as a means to distribute malware broadly. The reliance on open-source components and automated dependency management, while beneficial for productivity, also introduces points of vulnerability that can be exploited.

The rapid response in removing the malicious packages from crates.io highlights the importance of repository maintainers in safeguarding the software supply chain. However, the incident serves as a stark reminder that even well-maintained ecosystems are susceptible to compromise through social engineering or credential theft targeting individual maintainers.

In a broader context, this event reinforces the need for robust security practices throughout the software development lifecycle. This includes implementing multi-factor authentication for developer accounts, regularly auditing dependencies, employing static and dynamic analysis tools, and maintaining vigilance against unusual behavior in build processes. Such measures are crucial for mitigating the risks associated with the complex and interconnected nature of contemporary software development.

rustsupply chain attackmalwarecrates.iobuild script
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

CVE-2024-3094high

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly targeting the software development lifecycle (SDLC) supply chain by compromising developer tools, CI/CD pipelines, and open-source packages. Recent attacks like the ChainDrop npm worm demonstrate sophisticated methods to steal credentials, backdoor developer environments, and propagate malware. Securing the SDLC requires a shift from reactive code scanning to strict execution control and continuous visibility across developer endpoints, build pipelines, and cloud runtimes.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),