Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack

Summary

Aikido flags the largest Rust crate compromise yet: arrayref, append-only-vec and internment, poisoned with a proc-macro1 build-time dependency that fetches platform-specific payloads when compiled.

Why it matters

This incident coverage highlights observed attacker activity and practical defensive lessons.
Published
Collected

original ↗

Related coverage

back