注册并分享邀请链接,可获得视频播放与邀请奖励。

Rektoff
@rektoff_xyz
Rust-native security training for engineers, enterprises, and ecosystems.
加入 May 2023
286 正在关注    3.8K 粉丝
Heads up for anyone writing Rust today. The Rust Security Response Team just disclosed a supply chain attack. The popular arrayref crate was republished to pull in a malicious dependency that downloaded a payload through its build script. arrayref isn't obscure. If you or your dependencies pulled it recently, you'll want to check now. The malicious versions to look for: > arrayref 0.3.10 > internment 0.8.7 > append-only-vec 0.1.9 > proc-macro1, plus typosquats: proc-macro-en, aovine, arone, aronenao, tinymember All deleted from and the maintainer's account is locked. The team believes the author's credentials were compromised rather than the author acting maliciously. Full advisory, including the one-line command to scan your local cargo cache:
显示更多
0
6
155
50
转发到社区