Threat Intelligence

Malicious Code Found in Popular Rust Software Libraries Used by Millions

The Hacker News · 21 Aug 2026
Key Takeaway If your business uses custom-built software, ask your developers or vendors to confirm they monitor and vet third-party code dependencies for tampering, especially after supply chain attacks like this one.

The Rust Project has removed malicious versions of three popular Rust crates (pre-built code packages developers use to speed up software creation) after discovering a compromised maintainer account had published tampered releases. The affected packages—arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9—were all published by the same account owner.

The malicious versions included a disguised dependency with a name deliberately similar to a legitimate one, a technique known as typosquatting. This fake dependency contained a build script that would automatically download and run additional code from the internet the moment a developer compiled software using the affected package, without any obvious warning to the user.

Because these crates collectively have around 245 million downloads, the potential reach of this attack is significant, even though the malicious versions have now been pulled. This incident highlights a growing risk in modern software development: businesses often rely on hundreds of third-party code components, and a single compromised maintainer account can quietly introduce malware into products used by countless companies downstream.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.