
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
A compromised maintainer account published malicious versions of three Rust crates, which added a typosquatted dependency that downloaded and executed a remote payload during compilation. The affected releases were arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.…
















