Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack
aikido.dev | incident | #supply-chain | #threat-intelligence | #rust | #aikido | #backdoor | #open-source-security | #crates | #proc-macro1
Summary
Aikido flags the largest Rust crate compromise yet: arrayref, append-only-vec and internment, poisoned with a proc-macro1 build-time dependency that fetches platform-specific payloads when compiled.
Why it matters
This incident coverage highlights observed attacker activity and practical defensive lessons.
- Published
- Collected
Skip to content