Cybersecurity · August 23, 2026
A maintainer's account was compromised to publish new versions of three widely used Rust packages (arrayref, internment, and append-only-vec), adding a booby-trapped dependency whose build script downloaded and ran a remote payload during compilation. The Rust team quickly pulled the malicious versions from crates.io, but these libraries have racked up hundreds of millions of downloads combined, illustrating the scale of the risk to the software supply chain.
// source: thehackernews.com ↗