Article 5Z3ZP The malicious "rustdecimal" crate

The malicious "rustdecimal" crate

by
corbet
from LWN.net on (#5Z3ZP)
The Rust Blog warnsdevelopers of a malicious crate named rustdecimal, which wasevidently targeted at GitLab users who mistype rust_decimal.

The crate contained identical source code and functionality as thelegit rust_decimal crate, except for the Decimal::new function.

When the function was called, it checked whether the GITLAB_CIenvironment variable was set, and if so it downloaded a binarypayload into /tmp/git-updater.bin and executed it. The binarypayload supported both Linux and macOS, but not Windows.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments