
highMalware
Rust Supply Chain Attack Distributes Build-Time Malware via Compromised Crates.io Accounts
A supply chain attack targeting the Rust ecosystem has resulted in the deletion of malicious versions of three popular crates from crates.io. Analysis indicates a compromised maintainer account was used to push updates that introduced a typosquatted dependency. The build script of this dependency downloaded and executed a remote payload during the build process, potentially compromising downstream projects. The Rust Project confirmed the removal of the affected releases, though details regarding actor attribution and the origin of the remote payload remain unverified.
The Hacker News1 min read