diff --git a/.duplicate-id-guard b/.duplicate-id-guard index d1fefebb1..7f3a19e58 100644 --- a/.duplicate-id-guard +++ b/.duplicate-id-guard @@ -1,3 +1,3 @@ This file causes merge conflicts if two ID assignment jobs run concurrently. This prevents duplicate ID assignment due to a race between those jobs. -e60d6bb8f86955bec513d8a9205d803fbffdf187116af4a3003fa3f5dd08a13c - +54916b3421c30929d127132a061e0436bd9c9c395bec90db21c16c74f78dcab4 - diff --git a/crates/envlogger/RUSTSEC-0000-0000.md b/crates/envlogger/RUSTSEC-2023-0099.md similarity index 94% rename from crates/envlogger/RUSTSEC-0000-0000.md rename to crates/envlogger/RUSTSEC-2023-0099.md index 74645f6b3..90a85bfe8 100644 --- a/crates/envlogger/RUSTSEC-0000-0000.md +++ b/crates/envlogger/RUSTSEC-2023-0099.md @@ -1,21 +1,21 @@ -```toml -[advisory] -id = "RUSTSEC-0000-0000" -package = "envlogger" -date = "2023-08-16" -expect-deleted = true -references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] -categories = ["malicious"] - -[versions] -patched = [] -``` - -# `envlogger` was removed from crates.io for malicious code - -This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. - -This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. - -Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for -reporting this to the crates.io team! +```toml +[advisory] +id = "RUSTSEC-2023-0099" +package = "envlogger" +date = "2023-08-16" +expect-deleted = true +references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] +categories = ["malicious"] + +[versions] +patched = [] +``` + +# `envlogger` was removed from crates.io for malicious code + +This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. + +This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. + +Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for +reporting this to the crates.io team! diff --git a/crates/if-cfg/RUSTSEC-0000-0000.md b/crates/if-cfg/RUSTSEC-2023-0098.md similarity index 94% rename from crates/if-cfg/RUSTSEC-0000-0000.md rename to crates/if-cfg/RUSTSEC-2023-0098.md index c79b23a79..9e0388804 100644 --- a/crates/if-cfg/RUSTSEC-0000-0000.md +++ b/crates/if-cfg/RUSTSEC-2023-0098.md @@ -1,21 +1,21 @@ -```toml -[advisory] -id = "RUSTSEC-0000-0000" -package = "if-cfg" -date = "2023-08-16" -expect-deleted = true -references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] -categories = ["malicious"] - -[versions] -patched = [] -``` - -# `if-cfg` was removed from crates.io for malicious code - -This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. - -This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. - -Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for -reporting this to the crates.io team! +```toml +[advisory] +id = "RUSTSEC-2023-0098" +package = "if-cfg" +date = "2023-08-16" +expect-deleted = true +references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] +categories = ["malicious"] + +[versions] +patched = [] +``` + +# `if-cfg` was removed from crates.io for malicious code + +This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. + +This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. + +Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for +reporting this to the crates.io team! diff --git a/crates/lazystatic/RUSTSEC-0000-0000.md b/crates/lazystatic/RUSTSEC-2023-0097.md similarity index 94% rename from crates/lazystatic/RUSTSEC-0000-0000.md rename to crates/lazystatic/RUSTSEC-2023-0097.md index 6509dea34..59e94febe 100644 --- a/crates/lazystatic/RUSTSEC-0000-0000.md +++ b/crates/lazystatic/RUSTSEC-2023-0097.md @@ -1,21 +1,21 @@ -```toml -[advisory] -id = "RUSTSEC-0000-0000" -package = "lazystatic" -date = "2023-08-16" -expect-deleted = true -references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] -categories = ["malicious"] - -[versions] -patched = [] -``` - -# `lazystatic` was removed from crates.io for malicious code - -This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. - -This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. - -Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for -reporting this to the crates.io team! +```toml +[advisory] +id = "RUSTSEC-2023-0097" +package = "lazystatic" +date = "2023-08-16" +expect-deleted = true +references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] +categories = ["malicious"] + +[versions] +patched = [] +``` + +# `lazystatic` was removed from crates.io for malicious code + +This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. + +This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. + +Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for +reporting this to the crates.io team! diff --git a/crates/oncecell/RUSTSEC-0000-0000.md b/crates/oncecell/RUSTSEC-2023-0101.md similarity index 94% rename from crates/oncecell/RUSTSEC-0000-0000.md rename to crates/oncecell/RUSTSEC-2023-0101.md index a52d3d29f..c3d909300 100644 --- a/crates/oncecell/RUSTSEC-0000-0000.md +++ b/crates/oncecell/RUSTSEC-2023-0101.md @@ -1,21 +1,21 @@ -```toml -[advisory] -id = "RUSTSEC-0000-0000" -package = "oncecell" -date = "2023-08-16" -expect-deleted = true -references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] -categories = ["malicious"] - -[versions] -patched = [] -``` - -# `oncecell` was removed from crates.io for malicious code - -This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. - -This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. - -Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for -reporting this to the crates.io team! +```toml +[advisory] +id = "RUSTSEC-2023-0101" +package = "oncecell" +date = "2023-08-16" +expect-deleted = true +references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] +categories = ["malicious"] + +[versions] +patched = [] +``` + +# `oncecell` was removed from crates.io for malicious code + +This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. + +This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. + +Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for +reporting this to the crates.io team! diff --git a/crates/postgress/RUSTSEC-0000-0000.md b/crates/postgress/RUSTSEC-2023-0103.md similarity index 94% rename from crates/postgress/RUSTSEC-0000-0000.md rename to crates/postgress/RUSTSEC-2023-0103.md index 8142662df..eb18fc01e 100644 --- a/crates/postgress/RUSTSEC-0000-0000.md +++ b/crates/postgress/RUSTSEC-2023-0103.md @@ -1,21 +1,21 @@ -```toml -[advisory] -id = "RUSTSEC-0000-0000" -package = "postgress" -date = "2023-08-16" -expect-deleted = true -references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] -categories = ["malicious"] - -[versions] -patched = [] -``` - -# `postgress` was removed from crates.io for malicious code - -This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. - -This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. - -Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for -reporting this to the crates.io team! +```toml +[advisory] +id = "RUSTSEC-2023-0103" +package = "postgress" +date = "2023-08-16" +expect-deleted = true +references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] +categories = ["malicious"] + +[versions] +patched = [] +``` + +# `postgress` was removed from crates.io for malicious code + +This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. + +This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. + +Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for +reporting this to the crates.io team! diff --git a/crates/serd/RUSTSEC-0000-0000.md b/crates/serd/RUSTSEC-2023-0102.md similarity index 94% rename from crates/serd/RUSTSEC-0000-0000.md rename to crates/serd/RUSTSEC-2023-0102.md index f6ba9e4a3..60a0146bd 100644 --- a/crates/serd/RUSTSEC-0000-0000.md +++ b/crates/serd/RUSTSEC-2023-0102.md @@ -1,21 +1,21 @@ -```toml -[advisory] -id = "RUSTSEC-0000-0000" -package = "serd" -date = "2023-08-16" -expect-deleted = true -references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] -categories = ["malicious"] - -[versions] -patched = [] -``` - -# `serd` was removed from crates.io for malicious code - -This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. - -This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. - -Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for -reporting this to the crates.io team! +```toml +[advisory] +id = "RUSTSEC-2023-0102" +package = "serd" +date = "2023-08-16" +expect-deleted = true +references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] +categories = ["malicious"] + +[versions] +patched = [] +``` + +# `serd` was removed from crates.io for malicious code + +This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. + +This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. + +Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for +reporting this to the crates.io team! diff --git a/crates/xrvrv/RUSTSEC-0000-0000.md b/crates/xrvrv/RUSTSEC-2023-0100.md similarity index 94% rename from crates/xrvrv/RUSTSEC-0000-0000.md rename to crates/xrvrv/RUSTSEC-2023-0100.md index 7387b36cb..d68aa1f56 100644 --- a/crates/xrvrv/RUSTSEC-0000-0000.md +++ b/crates/xrvrv/RUSTSEC-2023-0100.md @@ -1,21 +1,21 @@ -```toml -[advisory] -id = "RUSTSEC-0000-0000" -package = "xrvrv" -date = "2023-08-16" -expect-deleted = true -references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] -categories = ["malicious"] - -[versions] -patched = [] -``` - -# `xrvrv` was removed from crates.io for malicious code - -This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. - -This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. - -Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for -reporting this to the crates.io team! +```toml +[advisory] +id = "RUSTSEC-2023-0100" +package = "xrvrv" +date = "2023-08-16" +expect-deleted = true +references = ["https://www.veracode.com/blog/rust-malware-staged-on-crates-io/"] +categories = ["malicious"] + +[versions] +patched = [] +``` + +# `xrvrv` was removed from crates.io for malicious code + +This crate was part of a typosquatting malware cluster published by the malicious user `amaperf` and contained a malware payload in build.rs to exfiltrate host information to the attacker. + +This advisory is to retrospectively document this attempted attack. The version information and download records of the malicious crate are no longer available. The related malicious crates have been yanked, and the malicious account has been banned. + +Thanks to [Veracode](https://www.veracode.com/) (formerly phylum)for +reporting this to the crates.io team!