{
  "id": 10932551,
  "title": "Rust malware in arrayref: how a build.rs ran a payload at compile time",
  "url": "https://urgent.news/2026/09/30/rust-malware-in-arrayref-how-a-build-rs-ran-a-payload-at-compile-time",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T11:46:44.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/axrisi/rust-malware-in-arrayref-how-a-buildrs-ran-a-payload-at-compile-time-e7f"
  },
  "original_language": "en",
  "account": "On August 20, 2026, a Rust malware called arrayref 0.3.10 infiltrated crates.io by exploiting one of its most-downloaded small crates. The security response team removed the malicious crate 86 minutes after its publication, but it had already affected many users. The incident highlights the importance of understanding how Cargo build scripts operate and the potential risks associated with it.",
  "summary": "On August 20, 2026, Rust malware reached crates.io through one of its most-downloaded small crates. arrayref 0.3.10 added a single dependency, proc-macro1 , a look-alike of the real proc-macro2 , and that crate's build script downloaded and started a binary while your project compiled. The Rust security response team deleted it 86 minutes later . If you write Rust, the mechanism matters more than…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}