daily cyber × ai intelligence

index

tagged

[rust]

2 editions · 3 items

August 22, 2026

  • The poisoned arrayref Rust crate is now linked to North Korean actors. Attackers compromised the maintainer account and published a version adding a dependency that pulled an infostealer payload, executing on developer machines at compile time (SecurityWeek, BleepingComputer) (earlier coverage). · Supply Chain
  • Two more malicious Rust crates impersonating proc-macro2 were caught by Nextron's artifact scanner, suggesting the crates.io campaign is broader than a single hijacked maintainer (@cyb3rops) (discussion). · Supply Chain

in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight

August 21, 2026

  • The Rust project published an advisory on the arrayref supply-chain attack, which deployed malicious crates impersonating proc-macro2: proc-macro1 v1.0.107 and proc-macro-en v1.0.10 (Rust Blog). Both carry the same malicious build.rs, executing a platform-specific payload from 23.254.165[.]112:9089 during cargo build, check or test; the Windows payload is a PowerShell backdoor that profiles the host and harvests Chromium browser credentials, with low VirusTotal detection (Nextron IOCs, The Hacker News). Build-time execution means CI runners are the primary blast radius. · Supply Chain

in Microsoft's Own Defender Driver Becomes the EDR Killer