crates.io dependency-confusion burst - 9 Rust crates targeting AWS, Mysten Labs, Replit, Proton, plus 4 generic-name typosquats, all flagged by OpenSSF Package Analysis on 2026-07-18
On 2026-07-18 the OpenSSF Package Analysis project flagged 9 Rust crates as malware - all yanked from crates.io within hours and mirrored into the GitHub Advisory Database as CWE-506 records. The 99.x.x version pins on mysten-metrics, amzn-codewhisperer-streaming-client, amzn-consolas-client, replit_ruspty, semantic-search-client, supertag, proton-pfff, and lsh are classic dep-confusion telltales. Every crate communicates with an attacker-controlled domain and executes commands on install.
Versions named here: 99.0.1, 99.1.0