Urgent.News

What's breaking now, across thousands of outlets.

Tech

Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat

In August 2026, a compromised version of the Rust crate arrayref was released on crates.io. Version 0.3.10 introduced a dependency on a malicious crate called proc-macro1, which contained a build script that downloaded and executed a remote binary during the compilation process. This malicious code ran at build time, allowing it to be triggered simply by compiling a project that used the compromised versions.

The crates.io team promptly removed the malicious versions, and the genuine arrayref and append-only-vec crates were maintained by droundy, whose GitHub account was later found to be compromised. The corresponding GitHub repositories and the entire droundy account no longer exist, rendering the upstream code inaccessible for inspection.

The malicious proc-macro1 crate was published by a username resembling David Tolnay's, but with forged author metadata pointing to a non-existent repository. The build script within proc-macro1 contained the payload, which stored its server address as base64 fragments and reassembled them at build time. The payload fetched an architecture-specific binary over a TLS connection without certificate validation, then executed it detached from the build process.

The malicious crate 0.3.10 was widely used as a transitive dependency, appearing in many Rust projects through various dependencies. The malicious code was introduced through a build script in proc-macro1, not within the arrayref crate itself. The malicious build script contained dependencies that were unusual for a token-parsing library, such as base64 decoding, TLS stack, and an HTTP client.

These dependencies, along with the modified documentation links and issue references, made the malicious crate appear as a legitimate drop-in replacement for proc-macro2. The build script executed the payload on every build on supported platforms, without any feature flags or environment checks to guard against it.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at stepsecurity.io →

More in Tech

More from Thursday 20 August →