News.Ycombinator
Supply Chain Attack Compromises Popular Rust Crates to Deliver Malware
Article Content
On August 20, 2026, a supply chain attack targeted the Rust ecosystem, compromising the widely used crates arrayref, append-only-vec, and internment. The attackers injected a malicious dependency, proc-macro1, which impersonated the legitimate proc-macro2 crate. During compilation, the build script executed, downloading and running a remote payload on the developer's machine. The attack affected over 245 million downloads of arrayref alone, with significant usage in cryptography and blockchain tools. The Rust Security Response Team removed the malicious versions and locked the maintainer's account, suspecting it was compromised. The malware is capable of exfiltrating sensitive information and establishing persistence on affected systems. The incident is noted for its scale and sophistication, marking one of the largest compromises in the Rust ecosystem to date.
Key Points: • The attack involved a malicious dependency that executed during compilation. • Over 245 million downloads of the arrayref crate were affected. • The malware can exfiltrate credentials from major web browsers.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.