Rust malware in arrayref: how a build.rs ran a payload at compile time
On August 20, 2026, Rust malware reached crates.io through one of its most-downloaded small crates. arrayref 0.3.10 added a single dependency, proc-macro1 , a look-alike of the real proc-macro2 , and that crate's build script downloaded and started a binary while your project compiled. The Rust security response team deleted it 86 minutes later . If you write Rust, the mechanism matters more than…
On August 20, 2026, a Rust malware called arrayref 0.3.10 infiltrated crates.io by exploiting one of its most-downloaded small crates. The security response team removed the malicious crate 86 minutes after its publication, but it had already affected many users. The incident highlights the importance of understanding how Cargo build scripts operate and the potential risks associated with it.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.