A supply-chain attack on the Rust ecosystem used a malicious typosquatted crate, rustdecimal, published on crates.io to target cloud-based development pipelines. SentinelLabs found 15 malicious versions, from 1.22.0 through 1.23.5, indicating repeated refinement by the attacker. The package checked for the GITLAB_CI environment variable and, when present, downloaded and executed a second-stage payload, turning compromised CI jobs into an entry point for broader downstream compromise.
The second-stage malware was identified as the Mythic Poseidon agent written in Go, with Linux and macOS support and backdoor functions including persistence, keylogging, file transfer, and screen capture. Researchers said the campaign also appeared to involve impersonation of a known Rust developer through a fake account to lend credibility to the poisoned dependency and encourage adoption. The malware communicated with a command-and-control endpoint at api.kakn[.]li, which resolved to 64.227.12[.]57, underscoring the risk that a single malicious package could infect trusted build environments and propagate into software supply chains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The attackers appeared to impersonate a known Rust developer using a fake account. SentinelLabs assessed this was likely intended to encourage trusted communities to reference the poisoned dependency.
Researchers found 15 malicious versions of the 'rustdecimal' crate, spanning versions 1.22.0 through 1.23.5. The version progression indicated the attackers were iteratively refining the malicious package over time.
SentinelLabs identified a typosquatted Rust crate named 'rustdecimal' on crates.io as part of the CrateDepression supply-chain attack. The package was designed to target GitLab CI environments and fetch a second-stage payload when the GITLAB_CI environment variable was present.
On 2022-05-19, SentinelLabs published its investigation into the CrateDepression Rust supply-chain attack, linking the malicious crate to a Go-based Mythic Poseidon agent. The report described the malware's Linux and macOS support, C2 infrastructure at api.kakn[.]li, and backdoor capabilities including persistence, keylogging, file transfer, and screen capture.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 44 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.