August 20, 07:15 UTC: a poisoned version of a package thousands of projects pull in landed in the Rust library registry
• 07:15 — arrayref 0.3.10 shipped with a dependency on the malicious crate proc-macro1
• 07:34 and 07:37 — the same with internment and append-only-vec
• 08:41–09:25 — the Rust security team deleted all three versions and locked the author's account
The poisoned versions were live for 86 to 107 minutes, and that is enough: the package downloaded its malicious payload during the build itself. Rust is what wallets, network nodes and Solana programs are written in, so anyone who builds their own code should go through their dependencies.
#security
🔗 My channels: Youtube • X • LinkedIn • Instagram • Threads
• 07:15 — arrayref 0.3.10 shipped with a dependency on the malicious crate proc-macro1
• 07:34 and 07:37 — the same with internment and append-only-vec
• 08:41–09:25 — the Rust security team deleted all three versions and locked the author's account
We do not believe the author of arrayref to be acting maliciously, but their computer or credentials are likely compromised
— Rust Security Response
The poisoned versions were live for 86 to 107 minutes, and that is enough: the package downloaded its malicious payload during the build itself. Rust is what wallets, network nodes and Solana programs are written in, so anyone who builds their own code should go through their dependencies.
#security
🔗 My channels: Youtube • X • LinkedIn • Instagram • Threads