Skip to content

Commit 4ca5630

Browse files
committed
Assigned RUSTSEC-2023-0097 to lazystatic, RUSTSEC-2023-0098 to if-cfg, RUSTSEC-2023-0099 to envlogger, RUSTSEC-2023-0100 to xrvrv, RUSTSEC-2023-0101 to oncecell, RUSTSEC-2023-0102 to serd, RUSTSEC-2023-0103 to postgress
1 parent 90c32bc commit 4ca5630

File tree

8 files changed

+148
-148
lines changed

8 files changed

+148
-148
lines changed

.duplicate-id-guard

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
This file causes merge conflicts if two ID assignment jobs run concurrently.
22
This prevents duplicate ID assignment due to a race between those jobs.
3-
e60d6bb8f86955bec513d8a9205d803fbffdf187116af4a3003fa3f5dd08a13c -
3+
54916b3421c30929d127132a061e0436bd9c9c395bec90db21c16c74f78dcab4 -
Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
1-
```toml
2-
[advisory]
3-
id = "RUSTSEC-0000-0000"
4-
package = "envlogger"
5-
date = "2023-08-16"
6-
expect-deleted = true
7-
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8-
categories = ["malicious"]
9-
10-
[versions]
11-
patched = []
12-
```
13-
14-
# `envlogger` was removed from crates.io for malicious code
15-
16-
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17-
18-
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19-
20-
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21-
reporting this to the crates.io team!
1+
```toml
2+
[advisory]
3+
id = "RUSTSEC-2023-0099"
4+
package = "envlogger"
5+
date = "2023-08-16"
6+
expect-deleted = true
7+
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8+
categories = ["malicious"]
9+
10+
[versions]
11+
patched = []
12+
```
13+
14+
# `envlogger` was removed from crates.io for malicious code
15+
16+
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17+
18+
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19+
20+
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21+
reporting this to the crates.io team!
Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
1-
```toml
2-
[advisory]
3-
id = "RUSTSEC-0000-0000"
4-
package = "if-cfg"
5-
date = "2023-08-16"
6-
expect-deleted = true
7-
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8-
categories = ["malicious"]
9-
10-
[versions]
11-
patched = []
12-
```
13-
14-
# `if-cfg` was removed from crates.io for malicious code
15-
16-
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17-
18-
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19-
20-
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21-
reporting this to the crates.io team!
1+
```toml
2+
[advisory]
3+
id = "RUSTSEC-2023-0098"
4+
package = "if-cfg"
5+
date = "2023-08-16"
6+
expect-deleted = true
7+
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8+
categories = ["malicious"]
9+
10+
[versions]
11+
patched = []
12+
```
13+
14+
# `if-cfg` was removed from crates.io for malicious code
15+
16+
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17+
18+
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19+
20+
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21+
reporting this to the crates.io team!
Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
1-
```toml
2-
[advisory]
3-
id = "RUSTSEC-0000-0000"
4-
package = "lazystatic"
5-
date = "2023-08-16"
6-
expect-deleted = true
7-
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8-
categories = ["malicious"]
9-
10-
[versions]
11-
patched = []
12-
```
13-
14-
# `lazystatic` was removed from crates.io for malicious code
15-
16-
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17-
18-
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19-
20-
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21-
reporting this to the crates.io team!
1+
```toml
2+
[advisory]
3+
id = "RUSTSEC-2023-0097"
4+
package = "lazystatic"
5+
date = "2023-08-16"
6+
expect-deleted = true
7+
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8+
categories = ["malicious"]
9+
10+
[versions]
11+
patched = []
12+
```
13+
14+
# `lazystatic` was removed from crates.io for malicious code
15+
16+
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17+
18+
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19+
20+
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21+
reporting this to the crates.io team!
Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
1-
```toml
2-
[advisory]
3-
id = "RUSTSEC-0000-0000"
4-
package = "oncecell"
5-
date = "2023-08-16"
6-
expect-deleted = true
7-
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8-
categories = ["malicious"]
9-
10-
[versions]
11-
patched = []
12-
```
13-
14-
# `oncecell` was removed from crates.io for malicious code
15-
16-
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17-
18-
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19-
20-
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21-
reporting this to the crates.io team!
1+
```toml
2+
[advisory]
3+
id = "RUSTSEC-2023-0101"
4+
package = "oncecell"
5+
date = "2023-08-16"
6+
expect-deleted = true
7+
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8+
categories = ["malicious"]
9+
10+
[versions]
11+
patched = []
12+
```
13+
14+
# `oncecell` was removed from crates.io for malicious code
15+
16+
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17+
18+
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19+
20+
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21+
reporting this to the crates.io team!
Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
1-
```toml
2-
[advisory]
3-
id = "RUSTSEC-0000-0000"
4-
package = "postgress"
5-
date = "2023-08-16"
6-
expect-deleted = true
7-
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8-
categories = ["malicious"]
9-
10-
[versions]
11-
patched = []
12-
```
13-
14-
# `postgress` was removed from crates.io for malicious code
15-
16-
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17-
18-
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19-
20-
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21-
reporting this to the crates.io team!
1+
```toml
2+
[advisory]
3+
id = "RUSTSEC-2023-0103"
4+
package = "postgress"
5+
date = "2023-08-16"
6+
expect-deleted = true
7+
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8+
categories = ["malicious"]
9+
10+
[versions]
11+
patched = []
12+
```
13+
14+
# `postgress` was removed from crates.io for malicious code
15+
16+
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17+
18+
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19+
20+
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21+
reporting this to the crates.io team!
Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
1-
```toml
2-
[advisory]
3-
id = "RUSTSEC-0000-0000"
4-
package = "serd"
5-
date = "2023-08-16"
6-
expect-deleted = true
7-
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8-
categories = ["malicious"]
9-
10-
[versions]
11-
patched = []
12-
```
13-
14-
# `serd` was removed from crates.io for malicious code
15-
16-
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17-
18-
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19-
20-
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21-
reporting this to the crates.io team!
1+
```toml
2+
[advisory]
3+
id = "RUSTSEC-2023-0102"
4+
package = "serd"
5+
date = "2023-08-16"
6+
expect-deleted = true
7+
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8+
categories = ["malicious"]
9+
10+
[versions]
11+
patched = []
12+
```
13+
14+
# `serd` was removed from crates.io for malicious code
15+
16+
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17+
18+
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19+
20+
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21+
reporting this to the crates.io team!
Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,21 @@
1-
```toml
2-
[advisory]
3-
id = "RUSTSEC-0000-0000"
4-
package = "xrvrv"
5-
date = "2023-08-16"
6-
expect-deleted = true
7-
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8-
categories = ["malicious"]
9-
10-
[versions]
11-
patched = []
12-
```
13-
14-
# `xrvrv` was removed from crates.io for malicious code
15-
16-
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17-
18-
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19-
20-
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21-
reporting this to the crates.io team!
1+
```toml
2+
[advisory]
3+
id = "RUSTSEC-2023-0100"
4+
package = "xrvrv"
5+
date = "2023-08-16"
6+
expect-deleted = true
7+
references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"]
8+
categories = ["malicious"]
9+
10+
[versions]
11+
patched = []
12+
```
13+
14+
# `xrvrv` was removed from crates.io for malicious code
15+
16+
This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker.
17+
18+
This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned.
19+
20+
Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for
21+
reporting this to the crates.io team!

0 commit comments

Comments
 (0)