Urgent.News

What's breaking now, across thousands of outlets.

Tech

Supply chain attack on arrayref (Rust blog)

The Rust blog reports on a malicious crate, called proc-macro1 , that was uploaded to the crates.io repository. Furthermore, we discovered that the popular arrayref crate had recently been republished and made to depend on this crate, with the most recent versions yanked. We have removed the malicious version and unyanked the maliciously-yanked versions. Other crates by that author ( internment ,…

On August 20, 2026, at 7:15 UTC, the Rust Security Response Team reported that the proc-macro1 crate was malicious. The team verified this, finding that the crate had a build script designed to download a malicious payload. The proc-macro1 crate, along with other similar crates such as proc-macro-en, aovine, arone, aronenao, and tinymember, were subsequently deleted from the crates.io repository.

Furthermore, the team discovered that the popular arrayref crate had been republished recently and made to depend on the malicious proc-macro1 crate. The most recent versions of arrayref were yanked, and the maliciously-yanked versions were unyanked. Several other crates linked to the same author, including internment and append-only-vec, were also found to be affected.

Consequently, these crates were removed as well, and the account was locked as a precautionary measure. Despite the team's belief that the arrayref author is not acting maliciously, their computer or credentials are likely compromised. The team is reaching out to the author to verify their situation.

The team recommends that users manually check their local dependencies to ensure they have not inadvertently pulled in these malicious crates. To do this, users can navigate to the ~/.cargo/registry/cache directory and examine the contents using a specific command.

The Rust Security Response Team extends their gratitude to the Research Team at Nextron Systems GmbH for initially identifying and reporting this issue. They also appreciate the contributions of Emily Albini, Manish Goregaokar, Marco Ieni, Tobias Bieniek, Ubiratan Soares, and Walter Pearce, whose expertise played a crucial role in the response to this supply chain attack.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at lwn.net →

More in Tech

DDR4 May Jump 50% on Tight Supply

The upward trend in legacy DRAM prices is expected to continue in the second half of this year. This is due to the tight supply of general-purpose DRAM as memory semiconductor (hereafter memory)…

  • DDR4 prices may increase by 50% in Q3, with 10% more rise in Q4
  • Supply of legacy DRAM tightens as manufacturers focus on HBM and server DRAM
  • Major customers like Nvidia and Google boost HBM demand plans, worsening supply shortage

More from Thursday 20 August →