The attack did not require a downstream vulnerability. Simply pulling in a tainted dependency and running a Cargo build was ...
Cargo, Rust's package manager, runs build scripts during compilation. This allowed proc-macro1 to identify the operating ...
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain ...
North Korean hackers compromised the popular arrayref package in a supply chain attack targeting the Rust ecosystem.
Rust’s security team has disclosed a supply-chain attack involving a malicious arrayref 0.3.10 release and several related ...
Researchers found significant infrastructure overlap between the attack on three Rust crates and recent North Korea-linked ...
A major software supply chain attack has struck the Rust ecosystem after threat actors hijacked widely used crates and ...
Rust deletes malicious releases of three crates after a proc-macro1 build script downloaded and ran a remote payload during ...
Wiz says the supply chain attack that poisoned arrayref, a Rust package present in roughly three-quarters of environments ...
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on ...
A monthly overview of things you need to know as an architect or aspiring architect. Unlock the full InfoQ experience by logging in! Stay updated with your favorite authors and topics, engage with ...
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...