| |
Malicious Rust Crate Arrayref Runs a Build-Time Payload
On August 20, 2026, a compromised version of the popular Rust crate arrayref (0.3.10) was published on crates.io with a malicious dependency on a typosquatted crate called proc-macro1 that downloaded and executed a remote binary during the build process. The attack leveraged a compromised maintainer account and used obfuscation techniques to hide the payload server address, with the malicious code running at build time whenever a project compiled. Crates.io has since removed both the malicious arrayref and proc-macro1 versions.
Read Full Article →
← More Tech news