Skip to main content

Share story

Security

Compromised Rust packages ran malware during compilation

Compromised Rust packages ran malware during compilation Image: Primary
Attackers compromised the maintainer account for the Rust crate arrayref and used it to publish a malicious release that executed malware during compilation, BleepingComputer reported. Two other crates, append-only-vec and internment, were also poisoned. The injected proc-macro1 dependency used a build script to select a payload for the host operating system. Crates.io removed the releases after the incident was reported. Developers who installed affected versions during the exposure window are advised to assume compromise.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...

Security
Security

ShinyHunters member reportedly detained in Jordan over FBI breach

ShinyHunters member Saif al-Din Khader, known as "Rey," was detained in Jordan and is cooperating to identify other hackers involved in the FBI breach, Reuters reported, citing sources. The hacking group claims to have stolen data...