Supply chain attack on arrayref (Rust blog)
Date:
Thu, 20 Aug 2026 13:26:01 +0000
Description:
The Rust blog reports on a malicious crate, called proc-macro1 , that was uploaded to the
crates.io repository. Furthermore, we discovered that the popular arrayref crate
had recently been republished and made to depend on this crate,
with the most recent versions yanked. We have removed the malicious
version and unyanked the maliciously-yanked versions. Other crates
by that author ( internment , append-only-vec ) were
also affected so we have done the same for those, and locked the
account as a precaution. We do not believe the author of arrayref to be acting maliciously, but their computer or
credentials are likely compromised, and we are attempting to
contact them.
======================================================================
Link to news story:
https://lwn.net/Articles/1089720/
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)