Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.

The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet

Small AI Models Gain Traction In places with unreliable networks

Small AI Models Gain Traction In places with unreliable networks Source: Hacker News

Airplane Boneyards List and Map

Airplane Boneyards List and Map Source: Hacker News