DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Supply chain attack on arrayref

Quality: 8/10 Relevance: 9/10

Summary

Rust's Security Response Team announced a supply chain attack involving a malicious build script in the proc-macro1 crate that affected arrayref and related crates. The malicious crate versions were deleted or unyanked, and the author's account was locked as a precaution. Developers are advised to audit dependencies and search local cargo caches for compromised crates.

🚀 Service construit par Johan Denoyer