Rust Supply Chain Attack Puts BuildTime Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from cratesio after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation The affected releases are arrayref 0310 internment 087 and appendonlyvec 019 all published from the same owner