your .env files are being SHIPPED to a lookalike domain and you probably typed the cargo add yourself
socket security just found 5 malicious rust crates sitting on http://crates. io since february 2026 - chrono_anchor, dnp3times, time_calibrator, time_calibrators, time-sync
they all pretend to be time utilities. they all impersonate http://timeapi. io. they all phone home to timeapis[.]io - one letter difference
the entire payload does one thing. reads your .env file. grabs every secret in it. sends it to a domain the attacker controls
not a zero day. not a kernel exploit. just a crate that looks like something youd cargo add at 1am without thinking
> "my dependencies are all popular and vetted"
these crates MIMIC the naming patterns of trusted libraries. chrono_anchor sits right next to chrono in your autocomplete. thats the whole trick.