
Rust supply chain attack targets build-time code in crates
A compromised crates.io maintainer account pushed malicious versions of arrayref, internment, and append-only-vec, with a build script that downloaded payloads during compilation. Here is how to check your lockfile and secure CI.