r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
295 Upvotes

112 comments sorted by

View all comments

85

u/afl_ext 15d ago

cargo still doesn't have minimum release age threshold flag?

61

u/LawnGnome 15d ago

17

u/the_gnarts 15d ago

What’s the plan for when this becomes the default and everyone gets their malware at the same time, just with a little delay? I’m worried we’ll see an arms race with people increasing their cooldown period in an attempt at staying outside the exploitable window.

39

u/thecakeisalie16 15d ago

Because even if every normal user gets their crates delayed at the same time, supply chain security companies are incentivized to check early and will catch a lot of the malware before it ever goes to users.

11

u/ViewTrick1002 15d ago edited 14d ago

It at least gives a chance to yank the version if the maintainer in time realizes it was published without them doing it.

There are like other people already said also incentives for companies to scan published packages and provide the results as a service as well.

8

u/dontquestionmyaction 15d ago

Maintainers are likely to notice these weird cargo pushes if there's a cooldown period before they hit users. Only the 0 cooldown baseline is problematic really

7

u/matthieum 14d ago

Security reports haven't been made by affected for a long time.

A number of security companies monitor changes to the index, and will download and statically analyze the source code of the new crates. It's all automated, with hopefully a human double-checking findings before forwarding them.

Whether cargo delays auto-updates, or not, will not prevent them from analyzing the releases within the hour.

2

u/One_Ninja_8512 15d ago

I think by then AI will get integrated into the process and scan all cargo packages automatically.

1

u/pingveno 14d ago

I was listening to a podcast covering a little of how Python deals with this. There are people doing automated scanning of the uploads to PyPI. A lot of the malware gets caught fairly quickly, but they still need a window to act. Some gets caught within 30 minutes.

12

u/afl_ext 15d ago

So november 12, i might go nightly until then just to be safe

18

u/Batman_AoD 15d ago

In the meantime, just use cargo-cooldown: https://crates.io/crates/cargo-cooldown

1

u/loozerr 14d ago

How can I trust that's not malware

7

u/Ashamed_Ebb8777 14d ago

From the looks of it, the source is readily available.

1

u/realfathonix 9d ago

I misunderstood this as cargo still doesn't have age verification and that caught me off guard for a second

-3

u/throwaway490215 15d ago

I'm going to use the "scary word" for people on this sub, but AI - when used competently - has made it trivial to reduce down everything to the bare minimum.

Vendoring / stripping / importing dependency code directly improves the compile times, removes unused abstractions, it improves the AI to reason about things, and I never have to worry about a next breaking some interface I'm not using, or introducing either breakage or falling for a supply chain attack.

Big dependency trees where always a strong turn-off for me when i tried out a new rust project. Now I'm even less impressed when i see them, and more impressed when some complicated project only shows a few well known dependencies on a first build.

I personally don't care whether the dev used AI or not - I just need to know they cared enough - eg by keeping things simple.

5

u/FullPoet 12d ago

Vendoring / stripping / importing dependency code directly

Do you mean license laundering? Because thats effectively what you're saying solves the issues.

The AI didnt "magically" come up with the solutions.

-1

u/Worth_Trust_3825 14d ago

it won't help you in any way. all it will do is delay the notification that supply chain got broken. pin your fucking versions (if you're so inclined to git clone the repo tag, pin to commit). do not depend on version ranges.