Cybersecurity researchers have identified five malicious Rust crates that disguise themselves as time-related utilities to exfiltrate .env file data. The affected packages, published on crates.io, include chrono_anchor, dnp3times, time_calibrator, time_calibrators, and time-sync. These crates impersonate the legitimate service timeapi.io and were released between late February and early March.
Want More Context? 🔎