Malware that ran on developers’ systems during compilation was introduced by hackers who gained access to the maintainer account for the popular Rust crate arrayref.
In the same supply-chain attack, the attacker additionally poisoned two further crates, append-only-vec and internment, within a 23-minute span.
With over 53 million downloads in the last 90 days, the arrayref crate is a well-liked Rust library that is utilized by blockchain, graphics, and cryptography tools. The malicious Rust crate releases were arrayref 0.3.10, append-only-vec 0.1.9, and internment 0.8.7, all of which were maintained by the same account, according to a report from application security firm StepSecurity.
While leaving the remaining upstream source code entirely unaltered, the hacker added a dependency on a package known as proc-macro1, a typosquat that mimicked the well-known proc-macro2 crate.
The researchers claim that during compilation, a script in proc-macro1 called “build.rs” is automatically run, rebuilding its infrastructure from base64-encoded pieces and choosing a payload that corresponds read more about Hackers poison arrayref Rust crate to push infostealer malware
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
