<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp" -->

---
title: Hackers Just Poisoned the Rust Supply Chain | Threat Wire
description: A weekly security news roundup covers a Rust crate supply chain attack where compromised maintainer GitHub accounts were used to publish malicious typosquatted...
canonical: https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers Just Poisoned the Rust Supply Chain | Threat Wire | daily.dev
og:description: A weekly security news roundup covers a Rust crate supply chain attack where compromised maintainer GitHub accounts were used to publish malicious typosquatted...
og:url: https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp
og:image: https://api.daily.dev/og/posts/GJHs5hBBp.png
og:image:alt: Hackers Just Poisoned the Rust Supply Chain | Threat Wire
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers Just Poisoned the Rust Supply Chain | Threat Wire

**[Hak5](https://daily.dev/sources/hak5)** · 5 min read · 0 upvotes · 0 comments

## Summary

A weekly security news roundup covers a Rust crate supply chain attack where compromised maintainer GitHub accounts were used to publish malicious typosquatted crates that executed during compilation and stole browser credentials from Chrome, Brave, and Edge via SQLite login databases; the malicious code was live for roughly two hours before removal, with possible North Korean attribution. Also covered: a severe Pioneer/Alpha Theta Rekordbox NFS vulnerability allowing arbitrary file downloads over local Wi-Fi (now patched), an 8-hour GitHub outage, new unauthenticated GitLab CVEs allowing modification or deletion of public projects and user data, Linux's 35th anniversary, and a wave of attacks on US water utilities (worst in Georgia) plus a 4-day outage at a British power plant linked to Iranian actors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.youtube.com/watch?v=A4DxpRTpkFk>

## Questions this post answers

### What happened in the recent Rust crate supply chain attack?

Attackers compromised the GitHub account of a maintainer who managed several Rust crates and published malicious typosquatted versions. The malicious code executed automatically during compilation, selected a payload based on the host operating system, and searched Chrome, Brave, and Edge SQLite login databases for stored credentials. The malicious packages were live for roughly two hours before being resolved, with researchers noting overlap with attacks attributed to North Korean hackers.

_Track fast-moving Rust supply chain incidents like this one on daily.dev to catch compromised crates early._

### What was the Rekordbox NFS vulnerability disclosed at Defcon?

A vulnerability in Rekordbox and software compatible with Pioneer DJ Link allowed any device on the same Wi-Fi network to download arbitrary files from a computer's hard drive when the NFS server mode was enabled, since the server let a user specify any file path. It affected Rekordbox on Mac, Windows, iOS, and Android, and maker Alpha Theta has since released a patch.

_Developers weighing local-network protocol exposure can follow disclosures like this one on daily.dev._

### What did the new GitLab CVEs allow attackers to do?

Newly discovered CVEs in GitLab allowed unauthenticated attackers to modify or delete public projects and user data without needing valid credentials. This came alongside a separate 8-hour GitHub outage on August 17, highlighting reliability and security concerns for teams relying on hosted git platforms.

_daily.dev helps teams evaluating git platform security stay on top of disclosures like these._

## Similar posts on daily.dev

- [This Week In Security: The Supply Chain Has Problems](https://daily.dev/posts/this-week-in-security-the-supply-chain-has-problems-e5yi4rj1g) · Hackaday · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#rust](https://daily.dev/tags/rust), [#gitlab](https://daily.dev/tags/gitlab)

[View this post on daily.dev](https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers Just Poisoned the Rust Supply Chain | Threat Wire","url":"https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp"},"datePublished":"2026-09-01T12:26:45.469Z","dateModified":"2026-09-01T12:28:00.549Z","description":"A weekly security news roundup covers a Rust crate supply chain attack where compromised maintainer GitHub accounts were used to publish malicious typosquatted...","image":"https://i.ytimg.com/vi/A4DxpRTpkFk/sddefault.jpg","thumbnailUrl":"https://i.ytimg.com/vi/A4DxpRTpkFk/sddefault.jpg","isAccessibleForFree":true,"articleSection":"Hak5","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Hak5","logo":"https://media.daily.dev/image/upload/s--NBqAwk3Z--/f_auto/v1710012451/logos/hak5","url":"https://daily.dev/sources/hak5"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,rust,gitlab","timeRequired":"PT5M","video":{"@type":"VideoObject","name":"Hackers Just Poisoned the Rust Supply Chain | Threat Wire","description":"A weekly security news roundup covers a Rust crate supply chain attack where compromised maintainer GitHub accounts were used to publish malicious typosquatted...","thumbnailUrl":"https://i.ytimg.com/vi/A4DxpRTpkFk/sddefault.jpg","uploadDate":"2026-09-01T12:26:45.469Z","duration":"PT5M","url":"https://api.daily.dev/r/GJHs5hBBp","embedUrl":"https://www.youtube.com/embed/A4DxpRTpkFk"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Hak5","item":"https://daily.dev/sources/hak5"},{"@type":"ListItem","position":3,"name":"Hackers Just Poisoned the Rust Supply Chain | Threat Wire"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/hackers-just-poisoned-the-rust-supply-chain-threat-wire-gjhs5hbbp#faq","mainEntity":[{"@type":"Question","name":"What happened in the recent Rust crate supply chain attack?","acceptedAnswer":{"@type":"Answer","text":"Attackers compromised the GitHub account of a maintainer who managed several Rust crates and published malicious typosquatted versions. The malicious code executed automatically during compilation, selected a payload based on the host operating system, and searched Chrome, Brave, and Edge SQLite login databases for stored credentials. The malicious packages were live for roughly two hours before being resolved, with researchers noting overlap with attacks attributed to North Korean hackers. Track fast-moving Rust supply chain incidents like this one on daily.dev to catch compromised crates early."}},{"@type":"Question","name":"What was the Rekordbox NFS vulnerability disclosed at Defcon?","acceptedAnswer":{"@type":"Answer","text":"A vulnerability in Rekordbox and software compatible with Pioneer DJ Link allowed any device on the same Wi-Fi network to download arbitrary files from a computer's hard drive when the NFS server mode was enabled, since the server let a user specify any file path. It affected Rekordbox on Mac, Windows, iOS, and Android, and maker Alpha Theta has since released a patch. Developers weighing local-network protocol exposure can follow disclosures like this one on daily.dev."}},{"@type":"Question","name":"What did the new GitLab CVEs allow attackers to do?","acceptedAnswer":{"@type":"Answer","text":"Newly discovered CVEs in GitLab allowed unauthenticated attackers to modify or delete public projects and user data without needing valid credentials. This came alongside a separate 8-hour GitHub outage on August 17, highlighting reliability and security concerns for teams relying on hosted git platforms. daily.dev helps teams evaluating git platform security stay on top of disclosures like these."}}]}
```

