Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
ID: 945a9454-94b5-5573-b13a-94a38b018215
STIX ID: report--945a9454-94b5-5573-b13a-94a38b018215
Feed Name: The Hacker News
Threat Score
A compromised crates.io maintainer account published malicious versions of arrayref, internment, and append-only-vec on 2026-08-20 that added a typosquatted dependency (proc-macro1) whose build script reconstructed a C2 address, disabled TLS validation, downloaded and executed OS-specific payloads during cargo build, and installed persistence; the releases were removed within 86–107 minutes, advisories and IoCs were published, and no confirmed widespread exploitation was reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
