Arrayref v0.3.10 and v0.3.11 compromised on crates.io

1 points by stevefan1999 ↗ HN
https://crates.io/crates/arrayref has a supply chain attack that runs malicious build script through a transient build-time dependency during `cargo build` with https://crates.io/crates/proc-macro-en/1.0.10/ (now deleted)

Some more context: https://github.com/rustsec/advisory-db/issues/3161

At the moment I cannot download the payloads anymore for further analysis.

0 comments

[ 3.5 ms ] story [ 6.6 ms ] thread

No comments yet.