← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 20, 2026 · 20:22via The Hacker News

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Brief

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.

The affected releases are arrayref 0.

  • 10, internment 0.
  • 7, and append-only-vec 0.
  • 9, all published from the same owner
Read more on The Hacker News