Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack
A supply chain attack compromised two popular Rust crates, arrayref and append-only-vec, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time.
Category: Vulnerabilities & Threats
评论
?
参与讨论