Supply Chain Attack: Backdoor Inserted into Millions of Downloaded Rust Crates
TL;DR
AI-generated
Malicious code was inserted into popular Rust crates like arrayref, internment, and append-only-vec. The malware establishes a backdoor on developer systems and collects system and browser data. The affected packages have been removed from Crates.io.
Source: golem.de
Same event
- Access Data at Risk: Worm Hijacks NPM Packages with Billions of Downloads
- Supply Chain Attack: Backdoor Inserted into Millions of Downloaded Rust Crates
Discussion
Log in to join the discussion.
No comments yet. Be the first!