吴说区块链|Aug 21, 2026 03:52
According to StepSecurity, malicious versions of Rust packages `arrayref`, `internment`, and `append-only-vec` were injected with malicious dependencies like `proc-macro1`, allowing attackers to download and execute remote payloads during project compilation via Rust's build scripts. The affected versions are `arrayref 0.3.10`, `internment 0.8.7`, and `append-only-vec 0.1.9`, with a total download count of approximately 264 million. The attack exposure window was from August 20, 2026, 07:11 to 09:25 (UTC). The malicious versions and six attacker-controlled packages have been removed from crates.io, and the publishing accounts have been locked. The safe versions are `0.3.9`, `0.8.6`, and `0.1.8`.
https://(wublock123.com)/news/rust-ecosystem-3-crates-supply-chain-attack-remote-code-execution-66935
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink