Hackers faked Rust developer David Tolnay's identity to poison the arrayref crate; Wiz links the attack's infrastructure to ...
The attack did not require a downstream vulnerability. Simply pulling in a tainted dependency and running a Cargo build was ...
On the afternoon of July 25, the Greek-owned supertanker Kiku docked at Qatar’s Mesaieed oil export terminal, a massive, ...
Cargo, Rust's package manager, runs build scripts during compilation. This allowed proc-macro1 to identify the operating ...
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain ...
North Korean hackers compromised the popular arrayref package in a supply chain attack targeting the Rust ecosystem.
Researchers found significant infrastructure overlap between the attack on three Rust crates and recent North Korea-linked ...
The attack involved injecting a dependency on a malicious package, proc-macro1, which impersonated the popular proc-macro2 ...
A major software supply chain attack has struck the Rust ecosystem after threat actors hijacked widely used crates and ...
Rust deletes malicious releases of three crates after a proc-macro1 build script downloaded and ran a remote payload during ...
Wiz says the supply chain attack that poisoned arrayref, a Rust package present in roughly three-quarters of environments ...
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on ...