Fixing Rust's supply chain security: The good, the bad and the ugly
kerkour.com · 2,753 words · saved by 1 readers
Last week, Rust was hit with a supply chain attack. Fortunately, within ~110 minutes, the 9 backdoored packages were removed, great job the Rust Security Response Team! Unfortauntely, it was
Last week, Rust was hit by a supply chain attack that reached packages that are downloaded more than 1,000,000 times per day. Fortunately, within ~110 minutes, the 9 backdoored packages were removed, great job the Rust Security Response Team! Unfortauntely, it was mostly avoidable and there is nothing preventing it to happen again (actually there probably is many other malicious packages on crates.io that just haven't been detected yet). I've spent a lot of time working on supply chain security (https://kerkour.com/rust-crate-backdoor from 2021,…
saved by
related reading
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Rewriting Bun in Rust | Bun Blogbun.com
- We should all be using dependency cooldownsblog.yossarian.net
- Software Supply Chain Security (Part 1)softwareanalyst.substack.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- State of DevSecOps | Datadogdatadoghq.com
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Mediummedium.com
- The Great Refactor | IFPifp.org
- Semantic Versioning - Rust Project Primerrustprojectprimer.com
- The Node-IPC Incidentnotes.ekzhang.com
- OWASP Foundation - The Open Source Foundation for Application Securityowasp.org
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io