Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
A supply chain attack targeting the Rust programming language ecosystem has been discovered, involving a compromised maintainer account publishing malicious versions of three crates – arrayref, internment, and append-only-vec. These crates, including a malicious version of proc-macro1, were designed to execute a remote payload during compilation, bypassing Cargo's normal dependency checks. The attack leveraged a typo-squatted dependency and a carefully crafted build script to deliver a stage-2 implant that steals browser credentials. The incident highlights a critical vulnerability in Cargo's dependency management and underscores the ongoing threat of supply chain attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
