Malicious Code Found in Popular Rust Software Libraries Used by Millions
The Rust Project has removed malicious versions of three popular Rust crates (pre-built code packages developers use to speed up software creation) after discovering a compromised maintainer account had published tampered releases. The affected packages—arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9—were all published by the same account owner.
The malicious versions included a disguised dependency with a name deliberately similar to a legitimate one, a technique known as typosquatting. This fake dependency contained a build script that would automatically download and run additional code from the internet the moment a developer compiled software using the affected package, without any obvious warning to the user.
Because these crates collectively have around 245 million downloads, the potential reach of this attack is significant, even though the malicious versions have now been pulled. This incident highlights a growing risk in modern software development: businesses often rely on hundreds of third-party code components, and a single compromised maintainer account can quietly introduce malware into products used by countless companies downstream.