#cratesIO
Together with PyPI, Maven Central, cratesio and other major package registries we signed a statement on sustainable open source infrastructure.
3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs.
#phpc #php
Registries like PyPI, Maven Central & crates.io power the ecosystem.

They can’t run on goodwill alone.

OpenSSF endorses the Joint Statement on Sustainable Stewardship.

👉 openssf.org/blog/2025/09...

#PreserveOpenSource
September 23, 2025 at 1:42 PM
How Safe is the Rust Ecosystem? A Deep Dive into crates.io

#cargo #cargodeny #cratesio #rustlang

mr-leshiy-blog.web.app/...
How Safe is the Rust Ecosystem? A Deep Dive into crates.io
mr-leshiy-blog.web.app
January 11, 2026 at 7:04 PM
i do wonder what the actual distribution of users would be for the “stable” and “unstable” branches of a pypi/cratesio

probably it would entirely be dictated by defaults (but i’m thinking with an oss hat and not corpy… but oss is probably the actual target)
May 15, 2026 at 1:18 PM
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

thehackernews.com/2026/05/trap...

#Cybersecurity #ThreatIntel #Vulnerability
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.
thehackernews.com
May 31, 2026 at 6:44 AM
Rustのパッケージを配る場所、crates.ioとは何か
https://papoo.work/doc/aa89441d2812cf99
#rust #cratesio #package_registry #library
Rustのパッケージを配る場所、crates.ioとは何か
papoo.work
May 22, 2026 at 10:51 PM
- the abi is literally a small fraction of the work though, a good rust plugin story has conventions for everything what comes to mind:
- installation mechanism (cratesio?)
- where does the plugin live? how do applications find plugins?
December 1, 2025 at 2:26 PM
Socket uncovered the TrapDoor campaign, which planted 34 malicious packages across npm, PyPI, and Crates.io to steal developer credentials

Disguised as legitimate tools, the malware extracts crypto wallet keys, SSH keys, GitHub tokens, and cloud credentials from Coinbase MetaMask, and Solana users
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
TrapDoor spread 34 malicious packages across npm, PyPI, and Crates.io, stealing developer credentials and enabling persistence.
thehackernews.com
May 26, 2026 at 5:29 AM
「 I just think it's pretty messed up that crates[.]io still requires a GitHub account to login, therefore to publish Rust packages. GitHub shouldn't be a shadow dependency of the language ecosystem 」
infosec.exchange/@mttaggart/1...

#rust #cratesio #github #opensource
Taggart :ifin: (@mttaggart@infosec.exchange)
I just think it's pretty messed up that crates[.]io still requires a GitHub account to login, therefore to publish Rust packages. GitHub shouldn't be a shadow dependency of the language ecosystem.
infosec.exchange
June 26, 2026 at 9:00 PM
Rustのパッケージを配る場所、crates.ioとは何か
https://papoo.work/doc/aa89441d2812cf99
#rust #cratesio #package_registry #library
Rustのパッケージを配る場所、crates.ioとは何か
papoo.work
May 20, 2026 at 10:40 AM
恶意Rust软件包在crates.io上窃取加密钱包密钥引发安全警告

多个恶意Rust软件包在crates.io平台被发现,这些包可窃取开发者的加密钱包密钥,暴露开源安全隐患。

📰 https://psa.ngo/news/malicious-rust-cratesio-crypto-wallet-key-theft/
Malicious Rust packages on Crates.io steal crypto wallet keys
Two malicious packages with nearly 8,500 downloads in Rust's official crate repository scanned developers' systems to steal cryptocurrency private keys and other secrets.
www.bleepingcomputer.com
September 26, 2025 at 11:10 PM
Rust team members and popular crate owners are being targeted with fake job and contract offers that lead to video calls, credential theft, and malicious package pushes. #Rust #cratesio #NorthKorea
Rust Team Members And Popular Crate Owners Targeted Via Video Calls
The Rust project warned that attackers are using fake job offers and contract opportunities to lure Rust developers and crate owners into video calls, where they try to steal credentials and push malicious packages. The campaign has been linked to earlier incidents involving the arrayref crate and other Rust developers, with...
www.hendryadrian.com
September 21, 2026 at 3:30 PM
Fake recruiter and collaborator offers are targeting Rust developers, tricking them into running malicious code or sharing credentials. The campaign is tied to Contagious Interview, linked to North Korean operators. #Rust #WaterPlum #NorthKorea
North Korea’s Job Interview Scam Runs Both Ways
Rust Project maintainers and crate developers are being targeted by attackers who pose as recruiters or collaborators to trick victims into running malicious code or revealing credentials. The campaign is linked to Contagious Interview (aka WaterPlum), a North Korean operation that has compromised thousands of devices and cryptocurrency wallets worldwide. #RustProject #ContagiousInterview #WaterPlum #cratesio
www.hendryadrian.com
September 21, 2026 at 1:15 PM
📢 Campagne ciblée contre les membres de la communauté Rust et propriétaires de crates populaires

Cet article émane de l'équipe crates.io et du groupe de travail sécurité. Il alerte sur une campagne active ciblant des membres prominents…

🔴 vérification factuelle basse
#Rust #CratesIo #Cyberveille
Campagne ciblée contre les membres de la communauté Rust et propriétaires de crates populaires
Cet article émane de l'équipe crates.io et du groupe de travail sécurité. Il alerte sur une campagne active ciblant des membres prominents de la communauté Rust et des propriétaires de crates populaires. Les attaquants utilisent des appels vidéo frauduleux comme vecteur d'infection, en se présentant sous des prétextes légitimes (offre d'emploi, projet, opportunité contractuelle).
cyberveille.ch
September 21, 2026 at 1:00 AM
Seriously #cratesio - you have no signing, provenance or transparency logging facilities in your registry. in 2026 ? WTH #rust 😞
September 9, 2026 at 3:56 AM
📢 Attaque supply chain Rust : trois crates hijackées sur crates.io, liens avec la Corée du Nord

Le 20 août 2026, Wiz Research publie une analyse technique d'une attaque de chaîne d'approvisionnement ciblant l'écosystème Rust via le…

🟢 vérification factuelle haute
#Rust #CratesIo #Cyberveille
Attaque supply chain Rust : trois crates hijackées sur crates.io, liens avec la Corée du Nord
Le 20 août 2026, Wiz Research publie une analyse technique d'une attaque de chaîne d'approvisionnement ciblant l'écosystème Rust via le registre officiel crates.io. L'article s'appuie également sur des données de Google Threat Intelligence.
cyberveille.ch
August 22, 2026 at 6:30 PM
Rust Supply Chain Attack: Poisoned Crates with 245M Downloads Execute Infostealer at Build Time

https://blindthoughts.com/rust-supply-chain-attack-arrayref-infostealer

#rust #supplychainattack #malware #cratesio #infosec
August 20, 2026 at 10:17 PM
DPRK typosquat backdoor infected 3 Rust crates (244M downloads) via build.rs infostealer. https://intel.threadlinqs.com/threat/TL-2026-2083 #ThreatIntel #procmacro1 #procmacroen #Cratesio
August 20, 2026 at 4:36 PM
Hackers hijacked the arrayref Rust crate maintainer account and pushed a malicious update that ran during compilation, also poisoning append-only-vec and internment in a supply-chain attack. #Rust #Cratesio #DPRK
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account for the Rust crate arrayref and pushed a malicious update that executed during compilation, while also poisoning append-only-vec and internment in the same supply-chain attack. The campaign affected widely used Rust projects and showed infrastructure overlaps with recent DPRK-linked attacks, prompting developers to check for compromise and rotate exposed secrets. #arrayref #append-only-vec #internment #proc-macro1 #StepSecurity #Wiz #Cratesio #Rust
www.hendryadrian.com
August 20, 2026 at 7:00 PM
It seems arrayref had its old versions yanked, thus leaving only the hacked version for resolution.

#rust #cratesio
August 20, 2026 at 8:19 AM
July 15, 2026 at 7:40 AM
How crates.io Source Links Close Rust Supply Chain Gaps

Read the full story here: https://newzlet.com/security/cratesio-source-links-rust-supply-chain-security/

#rust #supplychainsecurity #crates.io
July 15, 2026 at 7:30 AM