Malicious updates turned routine builds into a delivery system for infostealer malware Hackers slipped malware into several popular Rust packages this week, turning routine software builds into a route onto developers machines. The Rust Security Response Team disclosed the supply chain attack on Thursday after receiving a tip about a crate called proc macro1. An investigation found that its build script fetched malware from a remote server. The attack extended beyond a single dodgy crate....

Read the full article at The Register