Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Se muestra el contenido original; la traduccion localizada aun no esta disponible.
Qué ocurrió
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Por que importa
The launch may affect adoption and competitive positioning for Security; usage evidence is the next signal to watch.
Entidades afectadas
Ver evidencia
1 articulos · 1 informe original · 1 independientes
- The Hacker NewsFuente primaria · Respalda · EN · 100%Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads ↗
Afirmaciones
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads Observado
Conflictos
No se detectaron conflictos importantes en la evidencia disponible.
Cronología
- Primera publicación
- No verificado · 52/64%
Movimiento del mercado posterior al evento
La reacción del mercado aún no está disponible para este activo y periodo.