SlowMist Warns Rust Supply Chain Attack Spans Multiple Legitimate Crates
SlowMist warned that legitimate crates in the Rust ecosystem—[email protected], [email protected], and [email protected]—were targeted in a supply chain attack. A malicious dependency, proc-macro1, was injected into these packages, enabling the download and execution of cross-platform malware during the Cargo build process. The attack poses risks including remote code execution at build time, host information collection, persistence, and browser data gathering.