HomeCyber BalkansMalicious Rust Libraries Caught Transmitting OS Info to Telegram Channel

Malicious Rust Libraries Caught Transmitting OS Info to Telegram Channel

Published on

spot_img


Malicious Rust Libraries

In yet another sign that developers continue to be targets of software supply chain attacks, a number of malicious packages have been discovered on the Rust programming language’s crate registry.

The libraries, uploaded between August 14 and 16, 2023, were published by a user named “amaperf,” Phylum said in a report published last week. The names of the packages, now taken down, are as follows: postgress, if-cfg, xrvrv, serd, oncecell, lazystatic, and envlogger.

It’s not clear what the end goal of the campaign was, but the suspicious modules were found to harbor functionalities to capture the operating system information (i.e., Windows, Linux, macOS, or Unknown) and transmit the data to a hard-coded Telegram channel via the messaging platform’s API.

This suggests that the campaign may have been in its early stages and that the threat actor may have been casting a wide net to compromise as many developer machines as possible to deliver rogue updates with improved data exfiltration capabilities.

“With access to SSH keys, production infrastructure, and company IP, developers are now an extremely valuable target,” the company said.

This is not the first time crates.io has emerged as a target of a supply chain attack. In May 2022, SentinelOne uncovered a campaign dubbed CrateDepression that leveraged typosquatting techniques to steal sensitive information and download arbitrary files.

The disclosure comes as Phylum also revealed an npm package called emails-helper that, once installed, sets up a callback mechanism to exfiltrate machine information to a remote server and launches encrypted binaries that are shipped with it as part of a sophisticated attack.

The module, which was advertised as a “JavaScript library to validate email address against different formats,” has been taken down by npm but not before it attracted 707 downloads since it was uploaded to the repository on August 24, 2023.

“Data exfiltration is attempted via HTTP, and if this fails, the attacker reverts to exfiltrating data via DNS,” the company said. “The binaries deploy penetration testing tools like dnscat2mettle, and Cobalt Strike Beacon.”

“A simple action like running npm install can set off this elaborate attack chain, making it imperative for developers to exercise caution and due diligence as they carry out their software development activities.”

-REFERENCE: https://thehackernews.com/2023/08/developers-beware-malicious-rust.html

-K.Z



Source link

Latest articles

EU Develops Shield for 6G Network Security

The European Union has recently unveiled its latest security initiative, Shield-6G, aimed at safeguarding...

DragonForce Hackers Exploit Microsoft Teams Relays to Conceal Backdoor and Redirect C2 Traffic

Threat actors affiliated with the DragonForce ransomware have recently been identified utilizing a sophisticated...

LATAM Infrastructure Affected by Fortinet and Ivanti Exploits

A recent analysis has uncovered a meticulously coordinated campaign targeting government and financial sectors...

Hackers May Exploit SQL Server 2025 AI Features to Access Sensitive Data

A recent security analysis has unveiled alarming vulnerabilities in the newly launched Microsoft SQL...

More like this

EU Develops Shield for 6G Network Security

The European Union has recently unveiled its latest security initiative, Shield-6G, aimed at safeguarding...

DragonForce Hackers Exploit Microsoft Teams Relays to Conceal Backdoor and Redirect C2 Traffic

Threat actors affiliated with the DragonForce ransomware have recently been identified utilizing a sophisticated...

LATAM Infrastructure Affected by Fortinet and Ivanti Exploits

A recent analysis has uncovered a meticulously coordinated campaign targeting government and financial sectors...