Tag
#Crates.io
3 stories taggedCrates.io.

Vulnerabilities
Rust developers hit by supply-chain attack on arrayref crate
Attackers hijacked a maintainer account and slipped credential-stealing malware into three popular Rust libraries during a 1.5-hour window on August 20.
3 min read

Threat Intelligence
TrapDoor: The Supply Chain Campaign That Wants Your Whole Dev Environment, Not Just Your Secrets
A cross-registry malware campaign hitting npm, PyPI, and Crates.io is going after CI/CD pipelines, SSH trust chains, and AI coding assistant files — not just credentials on install.
3 min read

Threat Intelligence
TrapDoor Campaign Plants Credential Stealers Across npm, PyPI, and Crates.io
A coordinated operation seeded 34+ malicious packages across three registries since May 2026. If you ship code, this one is sitting in your dependency tree right now.
3 min read