Top
Best
New

Posted by abhisek 9 hours ago

Malicious Rust crate Arrayref runs a build-time payload(safedep.io)
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...

https://github.com/rustsec/advisory-db/issues/3161

339 points | 331 commentspage 4
FartyMcFarter 6 hours ago|
This is quite the egg on the face, given that Rust proponents keep telling us how it's great for writing secure software.
somerandomness 3 hours ago||
wow, what did payload do?
colingauvin 4 hours ago||
I hate cargo and npm. Why do we keep settling on arbitrary code execution in our build process?
freakynit 10 hours ago||
ahh... we now have nodejs ecosystem attack techniques migrating to other systems as well...
pixl97 8 hours ago|
It's not very surprising as the node attacks were very effective at gathering credentials.
frdev1786855380 1 hour ago||
[flagged]
cjg007 3 hours ago||
[flagged]
Booyaka101 7 hours ago||
[dead]
naniel 7 hours ago||
[dead]
AccountForSale 8 hours ago||
[flagged]
purplethreads 8 hours ago|
[flagged]
More comments...