Sources
Rust's arrayref Crate Was Backdoored Yesterday: a Typosquatted proc-macro1 Build Script Ran Remote Code During cargo build, Under 245M Downloads of Blast Radius
The Rust Project confirmed on 2026-08-20 that a compromised maintainer account published arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9, each pulling in a typosquat named proc-macro1 whose build script downloaded and executed an architecture-specific binary over a TLS connection that accepted any certificate. All three were yanked within 86 to 107 minutes, but the payload ran at compile time, so simply resolving the dependency was enough — nothing in the crates had to be called. arrayref has roughly 245 million all-time downloads and sits under blake3, winit, tiny-skia and large parts of the Solana and Ethereum toolchains; Wiz reports overlap with known DPRK campaigns.
↳ Follow the thread