Malicious Rust Crates Hijack 8.5K Downloads to Steal Crypto Keys
Two malicious packages in Rust's official crate repository, downloaded over 8,500 times, secretly scanned developers' systems for cryptocurrency private keys. Disguised as legitimate logging tools, the crates exfiltrated sensitive data to a rogue Cloudflare Worker endpoint. The incident underscores the persistent threat of supply chain attacks in open-source ecosystems.