[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmbl3jxHEYH1DrTiGM6GtpEzLXHpyseLePli1bdcx6Ws":3},{"article":4,"iocs":36,"watch_terms":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":10,"entities":15,"category_id":16,"category":17,"article_tags":20},"f77f861e-737c-4a0b-80ba-3e8dc6311d5a","Five Malicious Rust Crates and AI Bot Exploit CI\u002FCD Pipelines to Steal Developer Secrets","five-malicious-rust-crates-and-ai-bot-exploit-ci-cd-pipelines-to-steal-developer","Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat actors. The Rust packages, published to crates.io, are listed below - chrono_anchor dnp3times time_calibrator time_calibrators time-sync The crates, per Socket, impersonate timeapi.io and were published between late February and early March","Five malicious Rust crates were discovered on crates.io that steal developer secrets by exfiltrating .env files to attacker-controlled infrastructure. The packages impersonate legitimate time-related utilities and were published between late February and early March. This supply chain attack targets CI\u002FCD pipelines to compromise developer credentials and sensitive configuration data.",null,"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Ffive-malicious-rust-crates-and-ai-bot.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgzAdo0qx6xgUYxpWZkp4v30357zGX7ojSkN1vbfazb6D_JiXd9ksAHFNZJzY6pleKYV_HeYZcgJ48U36zUMPSJFR9bPUvFz18THXzTTnvhembJW9wrCypxj_2ttelgwbBwOD__5Yr-WGIBw1XthSLi6UZy3QtLZfmt7j_P8fOxZmm0PQwPAMCtNKkQzz1n\u002Fs1600\u002Frust.jpg","2026-03-11T05:12:00+00:00","2026-03-14T09:41:13.354083+00:00",[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":16,"icon":10,"name":18,"slug":19},"Supply Chain","supply-chain",[21,26,31],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":27},{"id":28,"icon":10,"name":29,"slug":30},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":32},{"id":33,"icon":10,"name":34,"slug":35},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[37,40,42,44,46,48],{"type":25,"value":38,"context":39},"chrono_anchor","Malicious Rust crate on crates.io",{"type":25,"value":41,"context":39},"dnp3times",{"type":25,"value":43,"context":39},"time_calibrator",{"type":25,"value":45,"context":39},"time_calibrators",{"type":25,"value":47,"context":39},"time-sync",{"type":49,"value":50,"context":51},"domain","timeapi.io","Domain impersonated by malicious crates for C2\u002Fexfiltration",[]]