Diamond Member ThaHaka 0 Posted August 20 Diamond Member Share Posted August 20 This is the hidden content, please Sign In or Sign Up The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/326331-h4ckn3wsrust-supply-chain-attack-puts-build-time-malware-in-crates-with-245-million-downloads/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.