Rust arrayref supply chain attack

Aug
21
Rust arrayref attack banner showing Cargo compiling arrayref 0.3.10 and the proc-macro1 1.0.107 typosquat before running its malicious build script and executing a payload.

The Rust arrayref attack turned a routine Cargo build into code execution

A poisoned dependency could execute code during compilation, so Rust teams should inspect every lockfile and Cargo cache touched on August 20.
4 min read