Supply chain attack on arrayref
- Rust: 13 events in the last 90 days
- Previous: earlier the same day · Investing in automated C to Rust translation
What happened
What happened On 2026-08-20 at 7:15 UTC we got a report that the proc-macro1 crate was malicious. The Rust Security Response Team verified this to be the case: the crate had a build script that was downloading a malicious payload. This crate proc-macro1 and others like it ( proc-macro-en , aovine , arone , aronenao , tinymember ) have been deleted. Furthermore, we discovered that the popular arrayref crate had recen…
Summary assembled by rule from the sources below