Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
ID: 391301fe-22c1-5763-8e3e-eb2c5feb0cab
STIX ID: report--391301fe-22c1-5763-8e3e-eb2c5feb0cab
Feed Name: The Hacker News
Security researchers found five malicious Rust crates on crates.io that impersonated time utilities to collect and exfiltrate .env secrets to attacker-controlled infrastructure, and uncovered an AI-powered bot (hackerbot-claw) that automatically exploited misconfigured GitHub Actions and a compromised Trivy VS Code extension to harvest and exfiltrate developer tokens and secrets; affected artifacts have been removed, CVE-2026-28353 was assigned, and users are advised to rotate credentials, audit CI/CD workflows, and remove malicious extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
