Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack

A supply chain attack compromised two popular Rust crates, arrayref and append-only-vec, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.
Category: Vulnerabilities & Threats

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论