Digest
CRITICAL

Rust Crates Compromised in Supply Chain Attack, Delivering Malware

Malicious versions of three popular Rust crates—arrayref, internment, and append-only-vec—were published to crates.io after a maintainer account was compromised. These trojanized versions included a typosquatted dependency that executed a remote payload during compilation, leading to the deployment of malware. The Rust Project has since deleted the affected releases, but the incident highlights ongoing software supply chain risks.

← Back to the feed

Trending Tags