
Researchers at Socket identified a targeted supply chain attack involving five malicious Rust crates and an autonomous AI bot designed to steal developer secrets.
Malicious Rust Crates
The five crates masqueraded as legitimate time-related utilities but were designed to exfiltrate sensitive .env files from developer environments and CI/CD pipelines.
chrono_anchordnp3timestime_calibratortime_calibratorstime-synctimeapi.io service, using a lookalike domain (timeapis[.]io) to receive stolen data.chrono_anchor hid its exfiltration logic within a guard.rs file invoked via an “optional sync” function.AI Bot Exploit: hackerbot-claw
Alongside the crates, an autonomous AI-powered bot named hackerbot-claw targeted major open-source repositories.
pull_request_target workflows in GitHub Actions to gain remote code execution and exfiltrate GitHub Personal Access Tokens (PATs).Recommendations for Developers
.env files.pull_request_target.#and #bots #ci/cd #hijack #malware #news #pipelines #rust #team — News
© Bulletproof Servers. All rights reserved.