frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Malicious Rust Crate Arrayref Runs a Build-Time Payload

https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/
40•abhisek•40m ago

Comments

aftbit•17m ago
Why do none of these hijacks embed runtime attacks? It seems like worming the build machines is the goal, rather than compromising downstream users.

It seems like we should be building and testing everything in bubblewrap or some other sandbox going forward.

Retr0id•14m ago
It usually takes some time for an updated dependency to actually get shipped to users in a release, by which time there's a good chance the attack has been noticed.
Panzerschrek•15m ago
Why this still happens? Why after many previous supply-chain attacks maintainers of package repositories still allow anyone uploading packages and pushing updates without security audit?
surajrmal•5m ago
Who is funding this security audit? Are folks supposed to volunteer their free time? It's a difficult coordination problem. The best folks have come up is to delay adopting new releases by a few days and hope your dependency is popular enough that a security firm audits it for you in that timespan. If you have enough money I suppose you can start employing llms to audit things for yourself.
praseodym•10m ago
Post on the Rust blog: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...

Discussion: https://news.ycombinator.com/item?id=49372853

ramimac•10m ago
Thread on the post from main rust blog: https://news.ycombinator.com/item?id=49372853

Direct post link: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...

Initial report: https://github.com/rustsec/advisory-db/issues/3161

Other vendor posts:

* https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-...

* https://research.jfrog.com/post/arrayref-proc-macro1-crates-...

* https://www.aikido.dev/blog/two-popular-rust-crates-arrayref...

christophilus•5m ago
Rust seems barely better than Node in this regard. Go or .Net or anything with a robust standard library seems like the way to go for most projects.
demibabs•3m ago
What does the malicious code actually do?
tsimionescu•3m ago
> arrayref is a small crate of four macros.

Why do so many languages fall intp this horrible practice?

Don't Paste the AI, please

https://dontpastetheai.com/
792•pjerem•5h ago•395 comments

AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html
301•emctech•3h ago•100 comments

Malicious Rust Crate Arrayref Runs a Build-Time Payload

https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/
45•abhisek•40m ago•9 comments

Show HN: I trained a 125M model to autocomplete piano on-device

https://simedw.com/2026/08/20/midi-autocomplete/
116•simedw•1h ago•30 comments

Windows brings out the Rorschach test in everyone (2003)

https://devblogs.microsoft.com/oldnewthing/20030825-00/?p=42803
275•luu•7h ago•99 comments

DiffusionGemma Technical Report

https://arxiv.org/abs/2608.00146
8•gmays•39m ago•0 comments

OpenRouter is joining Stripe

https://openrouter.ai/blog/announcements/openrouter-is-joining-stripe/
917•rvz•20h ago•469 comments

Seeing beyond BMI: Estimating cardiometabolic risk with smartphone imagery

https://research.google/blog/seeing-beyond-bmi-estimating-cardiometabolic-risk-with-smartphone-im...
25•leanderjanssen•3h ago•11 comments

Turns are Better than Radians (2022)

https://www.computerenhance.com/p/turns-are-better-than-radians
277•mayoff•12h ago•150 comments

Proof of Human (YC S23) Is Hiring a Member of Technical Staff

https://www.ycombinator.com/companies/proof-of-human/jobs/ZTZHEbb-member-of-technical-staff
1•timshell•2h ago

Google has stopped pushing Git tags for some Android source code

https://grapheneos.social/@GrapheneOS/117057099753905023
720•Animux•20h ago•278 comments

Go 1.27

https://go.dev/blog/go1.27
717•database64128•19h ago•217 comments

A faster way to calculate the day of the week

https://www.benjoffe.com/fast-day-of-week
209•gavide•3d ago•49 comments

Risk Engineering

https://risk-engineering.org/
26•throwaw12•3h ago•4 comments

Browser De-Slop

https://www.sacredheartsc.com/blog/browser-de-slop/
32•cullumsmith•1h ago•24 comments

A joke domain purchase turned in geopolitical warfare

https://sprocketfox.io/xssfox/2026/08/19/sondehub-and-war/
973•kareiva•1d ago•158 comments

Canonical Backs New Project to Translate Large C Codebases into Safe Rust

https://linuxiac.com/canonical-backs-new-project-to-translate-large-c-codebases-into-safe-rust/
13•datakan•51m ago•3 comments

UK internet age checks have boosted rogue adult sites, says Pornhub

https://www.ft.com/content/295c2eba-da29-434d-84e0-e9de3b0b1cc2
18•thm•1h ago•3 comments

Manabu Kosaka's Handmade Paper Sculptures

https://coca11272000.wixsite.com/manabukosaka
166•surprisetalk•23h ago•20 comments

Show HN: Streambench – Native Mac Client for Kafka and NATS

https://streambench.app
10•valentinprgnd•5d ago•2 comments

Unsloth Dynamic 3.0 GGUFs

https://unsloth.ai/docs/basics/dynamic-3.0-ggufs
305•jonesy827•19h ago•107 comments

Unlocking a locked/deactivated e-waste Cricut Maker

https://sprocketfox.io/xssfox/2026/07/01/cricut-unlock/
240•1e1a•18h ago•57 comments

The Chauffeur Problem

https://engines.egr.uh.edu/episode/1495
43•leowoo91•3d ago•22 comments

Casio F-B100W-1A

https://www.casio.com/uk/watches/casio/product.F-B100W-1A/
430•__fst__•22h ago•356 comments

Sol loves to cheat

https://jumploops.com/blog/sol-loves-to-cheat/
210•jumploops•1d ago•171 comments

Australia passes law to levy tech giants that fail to pay for local news

https://www.reuters.com/legal/litigation/australia-passes-law-levy-tech-giants-that-fail-pay-loca...
39•thm•2h ago•26 comments

Filtered Vector Search: What Acorn Fixes, and What Fixes Acorn

https://qdrant.tech/articles/filtered-vector-search-acorn/
8•softwaredoug•4d ago•0 comments

Geolocating a random island using geometry and CUDA programming

https://yassa9.github.io/osint/gralhix-004/
505•yassa9•1d ago•82 comments

PostgreSQL for Everything

https://www.raphaelbauer.com:443/posts/postgresql-everything/
411•karlmush•1d ago•237 comments

fx :Tiny, open, native coding agent.

https://fx.sh
299•handfuloflight•1d ago•128 comments