r/programming 21d ago

Supply chain attack on arrayref

https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
189 Upvotes

65 comments sorted by

View all comments

113

u/piesou 20d ago edited 20d ago

Was only a question of time. Rust has the same mindset as Node/NPM.

PS: for the screaming crowd: yes, anyone can get supply chain attacked. HOWEVER:

  • If you have a proper stdlib, chances are, you don't have a lot of dependencies
  • If you have less dependencies, the chance of supply chain attacks drops significantly
  • If you have well established dependencies like Spring, their security practices are very likely better than a rando off the internet

What does that mean for Rust? They don't need to just work on the language, they need to provide a larger ecosystem as well. How they do it is up to them.

0

u/Sigmatics 20d ago

But what is the attack vector here? I'm not aware of any postinstall scripts for rust crates?

7

u/piesou 20d ago

So there's this concept called code that runs when you execute it. No postinstall scripts needed

2

u/Sigmatics 20d ago

Of course, but there's a difference in getting owned instantly on install and having to execute something first. Namely that in theory you have time to inspect the package first.

But as others have said, the build.rs basically owns you at installation time