This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Rust · Archive · Week 8 · Feb 16 – 22, 2026

Crates.io malicious‑crate notification policy update

Worth knowingtooling

What changed
The crates.io team updated the policy for notifying users about malicious crates.
Production impact
The source does not say.
Try it
Search crates.io for a crate that has been flagged and observe the new notification message.
Source
blog.rust-lang.org/2026/02/13/crates.io-malicious-crate-update/

Understand it, then run it

Crates.io has changed how it tells people when a crate is found to be malicious. Before, every time a crate was flagged, a blog post was published. Now, most of those posts are removed because they were about crates that never actually ran in the wild. If a crate that is being used or exploited is removed, you will still see a blog post and a RustSec advisory. You can also get alerts by following the RustSec RSS feed.

Run it now

Todayrust
// This program demonstrates the current notification policy for malicious crates.
// It prints the recommended way to stay informed: subscribing to the RustSec RSS feed.
// No network access is performed; the program simply outputs guidance.

fn main() {
    println!("Crates.io no longer posts a blog entry for every malicious crate.");
    println!("Instead, subscribe to the RustSec advisory RSS feed for updates.");
}

What it printed when we ran it on Rust 1.98.1 (edition 2024)

Crates.io no longer posts a blog entry for every malicious crate.
Instead, subscribe to the RustSec advisory RSS feed for updates.

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed