CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Hackers poison arrayref Rust crate to push infostealer malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4781

As cited

Copy frozen at (site build).

threat intel

Hackers poison arrayref Rust crate to push infostealer malware

Attackers compromised the maintainer account of the popular arrayref Rust crate and injected malware that executed on developer systems during the build process. The compromise allowed the threat actors to distribute infostealer malware through a trusted supply chain vector. Developers who used the affected versions faced execution of malicious code in their build environments.

Why it matters: Rust developers and organizations shipping Rust code must audit their dependency trees for the compromised arrayref versions and rebuild clean artifacts, as their build systems and source repositories may have been exposed to the infostealer.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Hackers poison arrayref Rust crate to push infostealer malware

Attackers compromised the maintainer account of the popular arrayref Rust crate and injected malware that executed on developer systems during the build process. The compromise allowed the threat actors to distribute infostealer malware through a trusted supply chain vector. Developers who used the affected versions faced execution of malicious code in their build environments.

Why it matters: Rust developers and organizations shipping Rust code must audit their dependency trees for the compromised arrayref versions and rebuild clean artifacts, as their build systems and source repositories may have been exposed to the infostealer.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary