Popular Rust Packages With 244M Downloads Compromised to Run Malware

A major supply chain attack targeting the Rust ecosystem, in which two widely used crates, arrayref and append-only-vec, were hijacked to silently deliver malware the moment developers compiled their projects. Together, the two packages account for hundreds of millions of downloads, making this one of the largest Rust crate compromises ever recorded by download volume. […]

This article has been indexed from Cyber Security News

Read the original article: