Tech & AI News
Hacker News

Malicious Rust Crate Arrayref Runs a Build-Time Payload

A compromised release of the Rust crate arrayref (version 0.3.10) added a dependency on a typosquatted crate proc-macro1 (1.0.107); its build script downloads a TLS-served binary from 23.254.165.112 and executes it silently on both Unix and Windows. The malicious versions were removed after the crates.io team discovered the attack, which spread via yanked older releases that directed developers to the infected 0.3.10 package.