Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Compromised maintainer accounts published malicious Rust crates (arrayref, internment, append-only-vec) with typosquatted dependencies executing remote payload during compilation.
Read original coverage