Protect YourselfPublic
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Hacker News·August 20, 2026·1 min read
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Read full article on The Hacker News →Share this article
Follow broker incidents, regulatory actions & market intelligence
Stay ahead with CLEAREX.MARKET
View all intelligence →