Security researchers identified multiple malicious open source packages designed to impersonate widely used libraries in the Go and Rust ecosystems. In the Go ecosystem, two packages (github.com/bpoorman/uuid and github.com/bpoorman/uid) mimicked trusted UUID libraries, embedding a covert backdoor that exfiltrated data to a pastebin-style service using a hardcoded API token. These packages maintained legitimate functionality to avoid detection and remained accessible in public repositories for years, potentially exposing a large number of downstream projects to data theft.
Similarly, in the Rust ecosystem, a malicious crate named finch-rust was discovered impersonating the legitimate bioinformatics tool finch. This typosquatted package included a hidden dependency on sha-rust, a credential-stealing component that evolved rapidly over several iterations. The malicious code was triggered by a subtle function call, making it difficult to detect during routine code review. Both incidents highlight the ongoing threat of typosquatting and supply chain attacks in open source software, emphasizing the need for vigilant package vetting and prompt response from security teams.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Socket also published research on malicious Go packages impersonating Google's UUID library and exfiltrating data. The reference provides the existence of the disclosure but no further incident details in the supplied content.
Socket publicly reported the typosquatting and credential-exfiltration campaign involving 'finch-rust' and 'sha-rust', detailing the attacker’s impersonation tactics and malware behavior. The disclosure highlighted the growing sophistication of software supply chain threats in the Rust ecosystem.
After being notified of the supply chain attack, the Rust Security team removed the malicious packages from crates.io. This disrupted the credential-stealing campaign targeting Rust developers.
Over roughly two weeks, the attacker rapidly updated the malicious Rust package through eight versions while using fake GitHub repositories and spoofed commit authorship to appear legitimate. The payload was designed to trigger only during specific library operations and exfiltrate files such as .env, config.toml, and id.json to attacker-controlled infrastructure.
An attacker using the alias 'faceless' published a typosquatted Rust crate named 'finch-rust' to impersonate the legitimate 'finch' bioinformatics tool. The package included a hidden malicious dependency, 'sha-rust', designed to steal credentials and sensitive files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.