Výsledky hledání

výrobce: append-only-vec× v celém archivu zrušit filtry

3 karet z 3 položek CZ · EN/orig

1

Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper

Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-77649, CVE-2026-77650, CVE-2026-77651, Summary: CVE-2026-77649: The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. CVE-2026-77650: The append-only-vec crate 0.1.9 for Rust can trigger execution…

EPSS 0.00 CVSS 9.8 CVE-2026-77649 CVE-2026-77650 CVE-2026-77651 internment append-only-vec arrayref FI

· NCSC-FI · Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper

2

arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)

On August 20, 2026, malicious versions of three Rust crates were published to crates.io from the account of their maintainer, droundy: arrayref@0.3.10, internment@0.8.7 and append-only-vec@0.1.9. The Rust Security Response Team does not believe the maintainer published them, a...

arrayref internment append-only-vec US

tg: incident tg: varování tp: malware tp: dodavatelský řetězec

· Wiz Research · arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)