- Sources: primary, discussion
- Summary: The post, dated 2026-09-17, states the project's security response working group believes an ongoing campaign is targeting members of the rust-lang organisation and owners of popular crates, with the goal of obtaining publish access and shipping malware from an account crates.io already trusts. The campaign itself is the working group's stated belief rather than a published compromise: the post names no victim, no compromised account and no malicious crate, and reports no malware found on crates.io. The controls it offers are maintainer behaviour, including scepticism toward unsolicited contact, verification through known channels, and reporting attempts to the working group.
- Why it matters: The target is publish access rather than a bug, so the payoff is malware shipped from an account crates.io already trusts, and the only control named in the post is maintainer behaviour.
- Follow-up: Track whether the project names a compromised account, publishes indicators, or adds a publishing control beyond maintainer behaviour.
send feedback on this story