Related reading
Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation
The authors show that the classic trusting‑trust attack is not limited to compilers: by tampering with GNU strip they can inject a payload that propagates through NixOS's bootstrap and ends up in almost every binary of the final system. The attack succeeds on a real nixpkgs revision, building a full graphical installer while backdooring the majority of its binaries.
arXiv cs.SE (Software Engineering)arxiv.org1 minpaperHN24159Swap, ZRAM, Zswap and Hibernate on NixOS
Hacker News front pagematthewbrunelle.comHN7625Be alert: targeted attacks on prominent Rustaceans
The Mozilla Automation Team warns of a targeted social‑engineering campaign aimed at Rust community members and popular crate owners, using fake video‑call offers to deliver malware. They advise staying skeptical of cold outreach, using trusted call platforms, enabling MFA, and reporting any concerns to Rust security contacts.

