Hackers Compromise Rust Crate to Deliver Infostealer Malware
Attackers compromised the maintainer account of the Rust crate arrayref to inject malware that executes on developer systems during compilation, risking exposure of sensitive data.
Tag
5 results in the archive.
Attackers compromised the maintainer account of the Rust crate arrayref to inject malware that executes on developer systems during compilation, risking exposure of sensitive data.
A campaign distributing nearly 800 malicious npm packages with typo-squatted AI-generated names delivers a powerful RAT and infostealer targeting Windows, Mac, and Linux environments, posing a significant threat to developers and enterprises using npm packages.
A threat actor created almost 300 counterfeit GitHub repositories impersonating legitimate software projects to deliver infostealer malware, posing a significant supply chain threat.
A malicious version of the Jscrambler npm package containing infostealer malware was published and downloaded nearly 1,500 times, posing risks to developers and users of this client-side security tool.
The jscrambler npm package version 8.14.0 was compromised to install a Rust-based infostealer via a preinstall hook, impacting Windows, macOS, and Linux environments.