⤷ Title: Stealth Supply Chain Attack: Malicious Rust Crate Used Unpinned Dependency for Silent Payload Upgrades
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:33:32 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Credential Theft #Rust #sha_rust #supply chain attack #Typosquatting #Unpinned Dependency
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:33:32 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Credential Theft #Rust #sha_rust #supply chain attack #Typosquatting #Unpinned Dependency
Daily CyberSecurity
Stealth Supply Chain Attack: Malicious Rust Crate Used Unpinned Dependency for Silent Payload Upgrades
A Rust supply chain attack used typosquatting (finch-rust) and an unpinned dependency to silently update the sha-rust payload over two weeks, stealing credentials and private keys from developers.