[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$friguZ5fSfBcwITsOWwmoCyc_QoXy6L40VTQ3tVxib7I":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"29e39896-c0eb-4bed-919b-38de9959abdd","compromised-maintainer-account-delivers-build-time-malware-via-rust-crates","2aaaca44-4094-4a94-b008-0ac0040c7725","Compromised Maintainer Account Delivers Build-Time Malware via Rust Crates","A compromised Rust maintainer account was used to publish malicious versions of popular crates, affecting packages with a combined 245 million downloads. The attack exploited the trusted position of a legitimate account to inject a typosquatted dependency ('proc-macro1') that executed a remote payload at build time—meaning developers were compromised simply by compiling their project, without ever running the malicious code directly. This highlights the critical risk of transitive, build-time dependencies in modern software supply chains, where implicit trust in package registries can be weaponized. The incident underscores that supply chain attacks do not require a vulnerability in software itself—only access to a trusted publishing identity.","**Immediate actions:**\n- Audit all direct and transitive dependencies for recently published or unexpected new versions, especially those involving build scripts.\n- Enable multi-factor authentication (MFA) on all package registry and source control accounts used for publishing.\n- Pin dependency versions using cryptographic lock files (e.g., `Cargo.lock`) and validate checksums before building.\n\n**Long-term improvements:**\n- Implement a software composition analysis (SCA) tool in your CI\u002FCD pipeline to detect newly introduced or typosquatted dependencies automatically.\n- Establish a policy requiring code review and approval for any changes to build scripts (`build.rs`) in Rust projects.\n- Adopt a private internal registry or dependency mirroring strategy to control which package versions are permitted in builds.\n\n**Detection measures:**\n- Monitor build environments for unexpected outbound network connections originating from compilation or build script execution.\n- Set up alerts for newly published versions of critical dependencies so teams can review changes before adoption.\n- Integrate integrity verification (e.g., sigstore\u002Fcosign or crates.io checksum validation) into your build pipeline to detect tampered packages.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SSDF (SP 800-218): PW.4 – Reuse Existing, Well-Secured Software","NIST CSF DE.CM-3: Personnel activity is monitored","SLSA Supply Chain Levels for Software Artifacts – Level 2\u002F3 provenance requirements","GDPR Article 32: Security of Processing (where PII may be exfiltrated by payload)","NIST AC-2: Account Management (compromised maintainer account)","NIST SI-7: Software, Firmware, and Information Integrity","published","2026-08-20T22:20:52.984616+00:00","2026-08-20T22:20:52.918+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Frust-supply-chain-attack-puts-build.html","rust-supply-chain-attack-puts-build-time-malware-in-crates-with-245-million-down-41850b","Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"3bbd6c89-eadf-4651-8cf6-7fa8b7fd6123","2026-08-21","morning","ThreatNoir Morning Brief — August 21","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-21\u002Fthreatnoir-morning-brief-2026-08-21.mp3"]