< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-21T01:52:35+05:30

Rust Supply Chain Compromise Involves Build-Time Malware in High-Download Crates

A Rust supply chain attack injected build-time malware into three popular crates with 245 million downloads, exploiting compromised maintainer accounts to execute remote payloads during compilation. The malicious versions were rapidly removed, but the attack highlights vulnerabilities in dependency management and supply chain security.

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.

The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

Read original article

*** END OF TRANSMISSION ***