Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Cybersecurity · August 23, 2026

Cybersecurity·thehackernews.com

A maintainer's account was compromised to publish new versions of three widely used Rust packages (arrayref, internment, and append-only-vec), adding a booby-trapped dependency whose build script downloaded and ran a remote payload during compilation. The Rust team quickly pulled the malicious versions from crates.io, but these libraries have racked up hundreds of millions of downloads combined, illustrating the scale of the risk to the software supply chain.

// source: thehackernews.com ↗

Back to Blog