Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Contenu original affiche; la traduction localisee n'est pas encore disponible.
Ce qui s'est passé
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Pourquoi c'est important
The launch may affect adoption and competitive positioning for Security; usage evidence is the next signal to watch.
Entités concernées
Voir les preuves
1 articles · 1 publication d'origine · 1 independantes
- The Hacker NewsSource primaire · Confirme · EN · 100%Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads ↗
Affirmations
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads Observé
Divergences
Aucune divergence importante détectée dans les preuves disponibles.
Chronologie
- Premier signalement
- Non vérifié · 52/64%
Mouvement de marché suivant l'événement
La réaction du marché n'est pas encore disponible pour cet actif et cette fenêtre.