Radar · Rust · Archive · Week 7 · Feb 9 – 15, 2026
Crates.io malicious‑crate notification policy updated
Worth knowingecosystem
- What changed
- The Rust team updated the policy that notifies users about malicious crates.
- Production impact
- The source does not say.
- Try it
- Visit the crates.io policy page and review the new notification guidelines.
- Source
- blog.rust-lang.org/2026/02/13/crates.io-malicious-crate-update/
Understand it, then run it
The Rust team changed how they announce malicious crates on crates.io. Before, each time a crate was found to be malicious, a blog post would be published. Now, those blog posts are only made for crates that are actually used or exploited. For all removed crates, a RustSec advisory will still be published, and you can follow that RSS feed for updates.
Run it now
// This program prints a message about subscribing to the RustSec advisory RSS feed.
// It runs on Rust 1.98.1 (edition 2024) and produces the expected output.
fn main() {
println!("Subscribe to https://rustsec.org/advisories.rss for updates on malicious crates.");
}
What it printed when we ran it on Rust 1.98.1 (edition 2024)
Subscribe to https://rustsec.org/advisories.rss for updates on malicious crates.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed