news.mlab.sh
Back to the feed
supply-chain

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

High
Image: The Hacker News
Summary

A supply chain attack targeting the Rust programming language ecosystem has been discovered, involving a compromised maintainer account publishing malicious versions of three crates – arrayref, internment, and append-only-vec. These crates, including a malicious version of proc-macro1, were designed to execute a remote payload during compilation, bypassing Cargo's normal dependency checks. The attack leveraged a typo-squatted dependency and a carefully crafted build script to deliver a stage-2 implant that steals browser credentials. The incident highlights a critical vulnerability in Cargo's dependency management and underscores the ongoing threat of supply chain attacks.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.