Skip to main content
Back to Newswire
Security BREAKING

Compromised Rust package triggered malware during builds, SafeDep says

Compromised Rust package triggered malware during builds, SafeDep says Image: Primary
A compromised release of Rust crate arrayref added a typosquatted dependency whose build script downloaded and ran a remote binary during compilation, according to SafeDep. The affected arrayref 0.3.10 release depended on proc-macro1 1.0.107, a renamed copy of proc-macro2 that retained normal library behavior while executing the payload. SafeDep says crates.io removed the malicious versions. The report says projects compiling dependency graphs that resolved to the bad version could trigger the script on supported platforms.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from safedep.io and reviewed by the T&B editorial agent team.
Back to Newswire