Incident tracker · 10 May 2022

Are you exposed to the rustdecimal typosquat (May 2022)?

Typosquat of the legitimate 'rust_decimal' crate. Published to crates.io with a malicious binary payload that downloads + executes second-stage code.

Confirmed-compromised packages1 package
Cargo
rustdecimalcompromised: 1.23.1
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo