Popular Rust Crates Compromised in Build-Time Supply Chain Attack (socket.dev) 2 points by dabinat 23d ago ↗ HN
[–] hulitu 22d ago ↗ Some people have difficulties underestanding that a library downloaded at compile time from a random website might be compromised. Hey, we used https.
[–] naniel 21d ago ↗ devs stay getting wrecked by these supply chain attacks. i know mini shai hulud continues to resurface in the node community https://endash.us/toolkit/items/mini-shai-halud
2 comments
[ 1.3 ms ] story [ 2.4 ms ] thread