H
Hacker News
Top
Best
New
Posted by abhisek 9 hours ago
Malicious Rust crate Arrayref runs a build-time payload
(safedep.io)
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...
https://github.com/rustsec/advisory-db/issues/3161
339 points
|
331 comments
page 4
FartyMcFarter 6 hours ago
|
next
[-]
This is quite the egg on the face, given that Rust proponents keep telling us how it's great for writing secure software.
somerandomness 3 hours ago
|
prev
|
next
[-]
wow, what did payload do?
colingauvin 4 hours ago
|
prev
|
next
[-]
I hate cargo and npm. Why do we keep settling on arbitrary code execution in our build process?
freakynit 10 hours ago
|
prev
|
next
[-]
ahh... we now have nodejs ecosystem attack techniques migrating to other systems as well...
pixl97 8 hours ago
|
parent
[-]
It's not very surprising as the node attacks were very effective at gathering credentials.
frdev1786855380 1 hour ago
|
prev
|
next
[-]
[flagged]
cjg007 3 hours ago
|
prev
|
next
[-]
[flagged]
Booyaka101 7 hours ago
|
prev
|
next
[-]
[dead]
naniel 7 hours ago
|
prev
|
next
[-]
[dead]
AccountForSale 8 hours ago
|
prev
|
next
[-]
[flagged]
purplethreads 8 hours ago
|
prev
[-]
[flagged]
More comments...