Rust Crates Compromised in Supply Chain Attack, Delivering Malware
Malicious versions of three popular Rust crates—arrayref, internment, and append-only-vec—were published to crates.io after a maintainer account was compromised. These trojanized versions included a typosquatted dependency that executed a remote payload during compilation, leading to the deployment of malware. The Rust Project has since deleted the affected releases, but the incident highlights ongoing software supply chain risks.