North Korea-Linked Hackers Target Rust Software Supply Chain Arabian Post
Malicious versions of arrayref, internment and append-only-vec were published on crates. io, the official package registry for the Rust programming language, on August 20. The altered releases introduced a dependency called proc-macro1, designed to resemble the legitimate and widely used proc-macro2 package.
The affected versions were arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9. Investigators found that proc-macro1 contained a build script capable of downloading and executing a second-stage payload automatically when developers compiled software containing one of the compromised packages.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment