Supply chain attack on arrayref (Rust blog)
tech
LWN.net reports that a crate named proc-macro one was uploaded to crates dot io, Rust’s official package registry, and later used as a dependency by a newly republished version of the popular arrayref library. The malicious version has been removed and the affected releases were unyanked, while the author’s other crates, internment and append-only-vec, were also cleaned and the account locked as a precaution. The Rust blog does not think the arrayref maintainer acted maliciously, but suspects their computer or credentials were compromised and says they are trying to reach the maintainer.
Source: https://lwn.net/Articles/1089720/
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton