Two malicious packages were discovered in the Rust repository crates.io
Rust language developers have warned about the discovery of malicious code in the faster_log and async_println packages in the crates.io repository. The packages were uploaded to the repository on May 25 and have since been downloaded 8424 times. Attackers exploited the similarity of the package names with those of popular legitimate packages (e.g., faster_log instead of fast_log) to deliver modified clones, hoping that users […]
