Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the arrayref Rust crate to introduce infostealer malware. Learn more about the attack.
Hackers compromised the maintainer account of the widely used Rust crate arrayref, introducing malware that executed on developers' systems during compilation. This supply-chain attack also affected two other crates, append-only-vec and internment. With over 53 million downloads in the past 90 days, arrayref is integral to various cryptography and blockchain tools.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work