Malicious Rust crate Arrayref runs a $27 smart watch
It seems like worming the build machines is the goal, rather than compromising downstream users. It seems like it would be nice to know. Why do none of these hijacks embed runtime attacks? It seems like it would be nice to know.
The rust ecosystem is going to cause a Cambrian explosion of forges and if that is happening, Github will be the future. It would allow also non devs to join. It has nothing to do with Rust as a programming language, but meanwhile in the world of [language without a package manager], a monkey puppet glances awkwardly to the left.
Uhh no it isn't? This seems to be a bit higher (eg: putting in a full A4 / Letter sized page). Why do none of these hijacks embed runtime attacks? It seems like worming the build machines is the goal, rather than compromising downstream users. It seems like it would be nice to know. Just a heads up but datalist is not really a great solution if you need to pull in an external dependency replicable with 30 lines of code: