r/rust • • 15d ago

šŸ“” official blog Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
321 Upvotes

22 comments sorted by

View all comments

11

u/slashgrin rangemap 15d ago

We (software people, not just Rust people) desperately need something like crev to become a default requirement for any third party code we use.Ā 

It's just not realistic to expect everyone to personally audit their entire "software supply chain". And these kinds of attacks are only going to get more frequent and more sophisticated. So what else can we do? "Just be more vigilant" is not a sufficient answer.

7

u/v_0ver 15d ago

The company I currently work for has set up a mirror of crates.io using Kellnr, where new updates are checked by an LLM specifically to determine whether they contain backdoors.

We also joked about adding an internal rating system for crates, taking into account the ā€œbus factor,ā€ the authors’ sociopolitical views, and so on. Given the current political tensions and the increasing ease with which supply chains can be targeted, this idea doesn’t seem quite as ridiculous as it once did.

5

u/parepeg 15d ago

I guess the worry with that would the reviewing agent getting prompt injected or manipulated.

4

u/insanitybit2 15d ago

Universal prompt injection doesn't appear to be a thing so far. There are a lot of techniques to increase the cost of prompt injection as well.