Skip to main content
Back to Newswire
Security BREAKING

Compromised Rust packages ran malware during compilation

Compromised Rust packages ran malware during compilation Image: Primary
Attackers compromised the maintainer account for the Rust crate arrayref and used it to publish a malicious release that executed malware during compilation, BleepingComputer reported. Two other crates, append-only-vec and internment, were also poisoned. The injected proc-macro1 dependency used a build script to select a payload for the host operating system. Crates.io removed the releases after the incident was reported. Developers who installed affected versions during the exposure window are advised to assume compromise.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire