Typosquatting 2022 Incident #27 RUSTSEC-2022-0042

rustdecimal / CrateDepression

Estimated Financial Impact
<500 downloads
Blast Radius
Targeted GitLab CI; Mythic framework agent

What Happened

A typosquat of the rust_decimal crate specifically targeted GitLab CI environments by checking for the GITLAB_CI environment variable, then downloading a Mythic framework agent (a red team tool indicating APT-level targeting). The attacker impersonated a known Rust developer.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

2 Caught 0 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Missed Weaker ecosystem coverage
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← npm 287-package blockchain C2 BoltDB Go typosquat →