Skip to main content

Share story

Security

Compromised Rust package triggered malware during builds, SafeDep says

Compromised Rust package triggered malware during builds, SafeDep says Image: Primary
A compromised release of Rust crate arrayref added a typosquatted dependency whose build script downloaded and ran a remote binary during compilation, according to SafeDep. The affected arrayref 0.3.10 release depended on proc-macro1 1.0.107, a renamed copy of proc-macro2 that retained normal library behavior while executing the payload. SafeDep says crates.io removed the malicious versions. The report says projects compiling dependency graphs that resolved to the bad version could trigger the script on supported platforms.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from safedep.io and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Policy
Products Policy

Boeing awarded US$20-billion Navy fighter development contract

Boeing has been awarded a US$20-billion US Navy contract to develop the F/A-XX sixth-generation fighter, New Atlas reports. Boeing beat rival Northrop Grumman for the contract. The Navy needs a multirole aircraft that can operate...

Products
Products

Valley National agrees to buy Bluevine for $340M

Valley National Bancorp has agreed to acquire New Jersey-based Bluevine for $340M, CTech reports. Bluevine provides digital banking and payments services to 175K small and medium-sized businesses in the US. The acquisition would ...

Security AI
Security AI

Proofpoint links TA419 phishing campaigns to US AI policy targets

Proofpoint has attributed credential phishing campaigns against U.S. AI experts at think tanks, universities and legal organizations to TA419, a group it describes as China-aligned and motivated by espionage. Its analysis describe...