Back to Feed
Supply ChainMar 11, 2026

Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets

Five malicious Rust crates were discovered on crates.io that steal developer secrets by exfiltrating .env files to attacker-controlled infrastructure. The packages impersonate legitimate time-related utilities and were published between late February and early March. This supply chain attack targets CI/CD pipelines to compromise developer credentials and sensitive configuration data.

Summary

Five malicious Rust crates were discovered on crates.io that steal developer secrets by exfiltrating .env files to attacker-controlled infrastructure. The packages impersonate legitimate time-related utilities and were published between late February and early March. This supply chain attack targets CI/CD pipelines to compromise developer credentials and sensitive configuration data.

Indicators of Compromise

  • malware — chrono_anchor
  • malware — dnp3times
  • malware — time_calibrator
  • malware — time_calibrators
  • malware — time-sync
  • domain — timeapi.io