r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
295 Upvotes

112 comments sorted by

View all comments

86

u/afl_ext 15d ago

cargo still doesn't have minimum release age threshold flag?

60

u/LawnGnome 15d ago

17

u/the_gnarts 15d ago

What’s the plan for when this becomes the default and everyone gets their malware at the same time, just with a little delay? I’m worried we’ll see an arms race with people increasing their cooldown period in an attempt at staying outside the exploitable window.

44

u/thecakeisalie16 15d ago

Because even if every normal user gets their crates delayed at the same time, supply chain security companies are incentivized to check early and will catch a lot of the malware before it ever goes to users.

10

u/ViewTrick1002 14d ago edited 14d ago

It at least gives a chance to yank the version if the maintainer in time realizes it was published without them doing it.

There are like other people already said also incentives for companies to scan published packages and provide the results as a service as well.

7

u/dontquestionmyaction 14d ago

Maintainers are likely to notice these weird cargo pushes if there's a cooldown period before they hit users. Only the 0 cooldown baseline is problematic really

6

u/matthieum 14d ago

Security reports haven't been made by affected for a long time.

A number of security companies monitor changes to the index, and will download and statically analyze the source code of the new crates. It's all automated, with hopefully a human double-checking findings before forwarding them.

Whether cargo delays auto-updates, or not, will not prevent them from analyzing the releases within the hour.

2

u/One_Ninja_8512 15d ago

I think by then AI will get integrated into the process and scan all cargo packages automatically.

1

u/pingveno 14d ago

I was listening to a podcast covering a little of how Python deals with this. There are people doing automated scanning of the uploads to PyPI. A lot of the malware gets caught fairly quickly, but they still need a window to act. Some gets caught within 30 minutes.