Poisoned Rust crates used to deliver credential-stealing malwareThe Rust Security Response Team disclosed a supply-chain compromise involving arrayref, internment, append-only-vec, and typosquatted proc-macro1. Malicious releases stayed live on crates.io for 86 to 107 minutes, with build scripts fetching and executing payloads for Linux, Windows, Intel Macs