Supply chain attack on arrayref
On August 20, 2026, at 7:15 UTC, the Rust Security Response Team reported that the proc-macro1 crate was malicious. The team verified this, finding that the crate had a build script designed to download a malicious payload. The proc-macro1 crate, along with other similar crates such as proc-macro-en, aovine, arone, aronenao, and tinymember, were subsequently deleted from the crates.io repository.
Furthermore, the team discovered that the popular arrayref crate had been republished recently and made to depend on the malicious proc-macro1 crate. The most recent versions of arrayref were yanked, and the maliciously-yanked versions were unyanked. Several other crates linked to the same author, including internment and append-only-vec, were also found to be affected.
Consequently, these crates were removed as well, and the account was locked as a precautionary measure. Despite the team's belief that the arrayref author is not acting maliciously, their computer or credentials are likely compromised. The team is reaching out to the author to verify their situation.
The team recommends that users manually check their local dependencies to ensure they have not inadvertently pulled in these malicious crates. To do this, users can navigate to the ~/.cargo/registry/cache directory and examine the contents using a specific command.
The Rust Security Response Team extends their gratitude to the Research Team at Nextron Systems GmbH for initially identifying and reporting this issue. They also appreciate the contributions of Emily Albini, Manish Goregaokar, Marco Ieni, Tobias Bieniek, Ubiratan Soares, and Walter Pearce, whose expertise played a crucial role in the response to this supply chain attack.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.