Supply Chain Attack Compromises Popular Rust Crates, Injecting Malware into Developer Systems
Rapid Read

Supply Chain Attack Compromises Popular Rust Crates, Injecting Malware into Developer Systems

What's Happening? Two widely used Rust crates, `append-only-vec` (4 million downloads) and `arrayref` (244 million downloads), have been compromised in a supply chain attack. On August 20, a malicious dependency named `proc-macro1` was injected into these crates. This dependency, a typosquat of the
AI Generated
This may include content generated using AI tools. Glance teams are making active and commercially reasonable efforts to moderate all AI generated content. Glance moderation processes are improving however our processes are carried out on a best-effort basis and may not be exhaustive in nature. Glance encourage our users to consume the content judiciously and rely on their own research for accuracy of facts. Glance maintains that all AI generated content here is for entertainment purposes only.