Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack
A supply chain attack compromised two popular Rust crates, arrayref and append-only-vec, injecting a dependency on the malicious proc-macro1 package that downloads and executes a remote payload at build time. Category: Vulnerabilities & Threats