The Hacker News 中文 关注 Rust 供应链攻击将构建时恶意软件植入拥有 2.45 亿次下载的 crates Rust 项目已从 crates.io 删除了三个广泛使用的 Rust 包的恶意版本。此前,一个被入侵的维护者账户发布了包含该恶意依赖的更新,该依赖的拼写被恶意篡改(typosquatting),其构建脚本会在编译过程中下载并执行远程载荷。受影响的版本包括 arrayref 0.3.10、internment 0.8.7 和 append-only-vec 0.1.9,这些版本均由同一所有者发布。 Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads thehackernews.com The Hacker News 中文 RSS thenote.app