Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.

The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Next Post

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Related Posts
Total
0
Share