Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
What happened
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Why it matters
The launch may affect adoption and competitive positioning for Security; usage evidence is the next signal to watch.
Affected entities
View evidence
1 reports · 1 original report · 1 independent
- The Hacker NewsPrimary source · Supports · EN · 100%Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads ↗
Claims
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads Observed
Conflicts
No material conflict detected in the available evidence.
Timeline
- First reported
- Unverified · 52/64%
Market move following event
Market reaction is not yet available for this asset and time window.