
Compromised Rust Crate onering Steals Source Code During Application Builds
A major software supply chain attack has struck the Rust ecosystem after threat actors hijacked widely used crates and embedded a malicious build-time dependency that can steal source code, browser credentials, and cryptocurrency wallet data during application compilation. The incident affected arrayref version 0.3.10, append-only-vec version 0.1.9, and internment version 0.8.7. Together, the packages have […]
The post Compromised Rust Crate onering Steals Source Code During Application Builds appeared first on Cyber Security News.