<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rust on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/rust/</link><description>Recent content in Rust on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 23 Aug 2026 14:02:40 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/rust/index.xml" rel="self" type="application/rss+xml"/><item><title>Arrayref Rust Crate Hijacked to Run Malware While Your Project Compiled</title><link>https://hackingpassion.com/arrayref-rust-crate-build-script-attack/</link><pubDate>Sun, 23 Aug 2026 14:02:40 +0200</pubDate><guid>https://hackingpassion.com/arrayref-rust-crate-build-script-attack/</guid><description>&lt;p>Your Rust build pulled in a backdoor for &lt;strong>86 minutes&lt;/strong> on Thursday. Five versions with &lt;strong>246 million downloads&lt;/strong> between them were pulled in &lt;strong>16 seconds&lt;/strong>, leaving one poisoned release to land on.&lt;/p>
&lt;p>At 07:15 UTC on 20 August a new version of a Rust package called &lt;code>arrayref&lt;/code> showed up on crates.io. That package had been sitting there since August 2015. One file, &lt;strong>327 lines of code&lt;/strong>, nine kilobytes on disk, and it does one small job: it lets you grab a fixed number of bytes out of a longer run of them. &lt;strong>In almost eleven years it had never needed anything else to do that.&lt;/strong>&lt;/p></description></item></channel></rss>