{ads}

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads



August 21, 2026 at 01:52AM

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

from The Hacker News https://ift.tt/91mQxuo

0 Response to "Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads