- cross-posted to:
- kazkassukompais@group.lt
- lobsters@lemmy.bestiver.se
- cross-posted to:
- kazkassukompais@group.lt
- lobsters@lemmy.bestiver.se
If you recently used Cargo, make sure your system didn’t get infected. Here is another article with a little more info: https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
Well that’s the thing that scares me; I installed some Python packages (via uv) that compile Rust code upon installation.
I don’t know what they do, or how pip handles it. I had to go and dig, and figure out how they install packages and what the original projects use.