T1213.003

Data from Information Repositories: Code Repositories

discovered 2026-06-10

build.rs walks up from OUT_DIR until it finds the parent of a 'target' directory (the consuming Cargo project root) and runs 'git diff HEAD^ HEAD' to harvest proprietary source code from the victim's local repository, plus 'git log -n 1 --pretty=format:{...}' for commit metadata.

View on MITRE ATT&CK

Seen in packages