<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers poison arrayref Rust crate to push infostealer malware]]></title><description><![CDATA[<p dir="auto"><strong>Title:</strong> Supply Chain Attack Hits Rust Crate arrayref: Malicious Versions Deploy Infostealer</p>
<p dir="auto"><strong>Summary:</strong> The maintainer account for the popular Rust crate <code>arrayref</code> was compromised, leading to the publication of trojanized versions designed to infect developer machines with infostealer malware during the build process.</p>
<p dir="auto"><strong>Body:</strong></p>
<p dir="auto">The XploitLK community is tracking a significant supply chain incident affecting the Rust ecosystem. The maintainer account for the widely used <code>arrayref</code> crate was compromised, allowing attackers to publish malicious versions of the package. These poisoned releases were engineered to execute payloads on developers' systems automatically during the compilation phase.</p>
<p dir="auto">While the exact scope of the compromise is still being assessed, the attack vector highlights the ongoing risks associated with open-source dependency management. The malicious code was designed to deploy an infostealer, a type of malware that exfiltrates sensitive data such as credentials, environment variables, and developer secrets from infected workstations.</p>
<p dir="auto">According to the original report, the malicious versions have been removed from the official <a href="http://crates.io" target="_blank" rel="noopener noreferrer nofollow ugc">crates.io</a> registry. However, developers who have already used the affected versions in their projects should immediately rotate any credentials or tokens that may have been exposed on their build machines and audit their dependency lock files for the vulnerable version numbers.</p>
<p dir="auto">The incident serves as a critical reminder for the community to verify package integrity, monitor for unexpected version updates, and consider using checksum verification and sandboxed build environments to mitigate such risks.</p>
<p dir="auto">For full technical details and the list of affected versions, refer to the original article from BleepingComputer: <a href="https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware</a></p>
]]></description><link>https://xploitlk.com/topic/47/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 11:43:29 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/47.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 21 Aug 2026 01:54:46 GMT</pubDate><ttl>60</ttl></channel></rss>