Back Ground.News Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]
Key Points of the News: Affected Packages: Malicious versions of Rust arrayref Crates (@0.3.10), append-only-vec (@0.1.9) and internment (@0.8.7) were published in crates.io on August 20, 2026. Scope of the library: La crate arrayref records more than 244 million accumulated downloads and is present in three quarters of the environments where Rust operates.Security Response: The Rust Security Response Team removed the packages committed after re…
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner
Wiz says the supply chain attack that poisoned arrayref, a Rust package present in roughly three-quarters of environments running Rust, has drawn comparisons with recent North Korean operations. The harmful update hid a backdoor that steals login information inside a code designed to run automatically when users compile projects. So, anyone who compiled a project on Thursday may now have exposed their computer and secrets. Why is North Korea be…
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation. Within a 23-minute window, the attacker also poisoned two other crates, append-only-vec and internment, in the same supply-chain attack. The arrayref crate is a popular Rust library with more than 53 million downloads […] Thank you for subscribing to our RSS feed! The post Hackers poi…
To view factuality data please Upgrade to Premium
To view ownership data please Upgrade to Vantage
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
