FlashFeed
๐Ÿ’ป
๐Ÿ’ป Technology

Malicious Rust crate "arrayref" executed malware at build time

A malicious package named "arrayref" was discovered in the Rust crate registry, executing a harmful payload at build time using a procedural macro mechanism. The attack targeted developers' machines without their knowledge during the compilation stage. This represents a supply-chain attack on open-source software infrastructure.

Comments

No comments yet