Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
Five malicious Rust crates that pose as time-related tools and send.env file data to threat actors have been found by cybersecurity experts.
The following is a list of Rust packages that have been published to crates.io:
chrono_anchor
dnp3times
time_calibrator
time_calibrators
time-sync
According to Socket, the crates were released between late February and early March 2026 and pose as timeapi.io. Based on the usage of the same exfiltration technique and the lookalike domain ("timeapis[.]io") to store the stolen data, it is determined to be the work of a single threat actor.
According to security researcher Kirill Boychenko, the crates' primary behavior is credential and secret theft, even if they pretend to be local time utilities. They try to gather private inf...


