Schwachstellenklasse
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
Quellen
- https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref
- https://github.com/rustsec/advisory-db/issues/3161
- https://rustsec.org/advisories/RUSTSEC-2026-0260.html
- https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/
- https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.