Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
Five malicious Rust crates were discovered on crates.io that steal developer secrets by exfiltrating .env files to attacker-controlled infrastructure. The packages impersonate legitimate time-related utilities and were published between late February and early March. This supply chain attack targets CI/CD pipelines to compromise developer credentials and sensitive configuration data.
Summary
Five malicious Rust crates were discovered on crates.io that steal developer secrets by exfiltrating .env files to attacker-controlled infrastructure. The packages impersonate legitimate time-related utilities and were published between late February and early March. This supply chain attack targets CI/CD pipelines to compromise developer credentials and sensitive configuration data.
Indicators of Compromise
- malware — chrono_anchor
- malware — dnp3times
- malware — time_calibrator
- malware — time_calibrators
- malware — time-sync
- domain — timeapi.io