Supply chain attack on arrayref (Rust blog)
The Rust blog reports on a malicious crate, called proc-macro1 , that was uploaded to the crates.io repository. Furthermore, we discovered that the popular arrayref crate had recently been republished and made to depend on this crate, with the most recent versions yanked. We have removed the malicious version and unyanked the maliciously-yanked versions. Other crates by that author ( internment ,…
We haven't written up this one. LWN has the full story — the link below goes straight to it.