Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.

The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Attack Update: Top 5 Attack-IPs auf doode.info – 10.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 144.76.19.72 — 1029 requests (recent log) 89.167.35.212 — 460 requests (recent log) 74.7.241.36 — 242 requests (recent

Dutch Train Map Simulator

Dutch Train Map Simulator Source: Hacker News

Altair Basic Interpreter Source Code (1975) [pdf]

Altair Basic Interpreter Source Code (1975) [pdf] Source: Hacker News