Conversion Hackers
Fealse: Tech News
Researchers Uncover Rust Supply-Chain Attack Targeting Cloud CI Pipelines
  • Security

Researchers Uncover Rust Supply-Chain Attack Targeting Cloud CI Pipelines

  • May 20, 2022
  • admin
Total
0
Shares
0
0
0

A case of software supply chain attack has been observed in the Rust programming language’s crate registry that leveraged typosquatting techniques to publish a rogue library containing malware.

Cybersecurity firm SentinelOne dubbed the attack “CrateDepression.”

Typosquatting attacks take place when an adversary mimics the name of a popular package on a public registry in hopes that developers will accidentally download the malicious package instead of the legitimate library.

In this case, the crate in question is “rustdecimal,” a typosquat of the real “rust_decimal” package that’s been downloaded over 3.5 million times to date. The package was flagged earlier this month on May 3 by Askar Safin, a Moscow-based developer.

According to an advisory published by the Rust maintainers, the crate is said to have been first pushed on March 25, 2022, attracting fewer than 500 downloads before it was permanently removed from the repository.

Like prior typosquatting attacks of this kind, the misspelled library replicates the entire functionality of the original library while also introducing a malicious function that’s designed to retrieve a Golang binary hosted on a remote URL.

Specifically, the new function checks if the “GITLAB_CI” environment variable is set, suggesting a “singular interest in GitLab continuous integration (CI) pipelines,” SentinelOne noted.

The payload, which is equipped to capture screenshots, log keystrokes, and download arbitrary files, is capable of running on both Linux and macOS, but not Windows systems. The ultimate goals of the campaign are unknown as yet.

CyberSecurity

While typosquatting attacks have been previously documented against NPM (JavaScript), PyPi (Python), and RubyGems (Ruby), the development marks an uncommon instance where such an incident has been discovered in the Rust ecosystem.

“Software supply-chain attacks have gone from a rare occurrence to a highly desirable approach for attackers to ‘fish with dynamite’ in an attempt to infect entire user populations at once,” SentinelOne researchers said.

“In the case of CrateDepression, the targeting interest in cloud software build environments suggests that the attackers could attempt to leverage these infections for larger scale supply-chain attacks.”



Total
0
Shares
Share 0
Tweet 0
Pin it 0
admin

Previous Article
Create magical portraits using just one umbrella with these 5 different set ups
  • Photography

Create magical portraits using just one umbrella with these 5 different set ups

  • May 20, 2022
  • admin
View Post
Next Article
Faster and Bigger: 2022 Amazon Fire 7 and Kids tablets launched
  • Reviews

Faster and Bigger: 2022 Amazon Fire 7 and Kids tablets launched

  • May 20, 2022
  • admin
View Post
You May Also Like
Hackers Come Home to Vibrant Community
View Post
  • Security

Hackers Come Home to Vibrant Community

  • admin
  • August 15, 2022
Most Q2 Attacks Targeted Old Microsoft Vulnerabilities
View Post
  • Security

Most Q2 Attacks Targeted Old Microsoft Vulnerabilities

  • admin
  • August 15, 2022
Transitioning From VPNs to Zero-Trust Access Requires Shoring Up Third-Party Risk Management
View Post
  • Security

Transitioning From VPNs to Zero-Trust Access Requires Shoring Up Third-Party Risk Management

  • admin
  • August 15, 2022
Credential Theft
View Post
  • Security

Credential Theft Is (Still) A Top Attack Method

  • admin
  • August 15, 2022
The Industry Must Better Secure Open Source Code From Threat Actors
View Post
  • Security

How and Why to Apply OSINT to Protect the Enterprise

  • admin
  • August 15, 2022
Black Hat and DEF CON Roundup
View Post
  • Security

Black Hat and DEF CON Roundup

  • admin
  • August 15, 2022
SOVA Android Banking Trojan
View Post
  • Security

SOVA Android Banking Trojan Returns With New Capabilities and Targets

  • admin
  • August 15, 2022
Black Hat USA 2022: Burnout, a significant issue
View Post
  • Security

Black Hat USA 2022: Burnout, a significant issue

  • admin
  • August 15, 2022

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories
  • Apps
  • Games
  • How To
  • News
  • Photography
  • Reviews
  • Security

Input your search keywords and press Enter.