Malicious arrayref 0.3.10 on crates.io ran a payload at build time
On August 20, 2026, malware reached crates.io via arrayref 0.3.10, which added a dependency on proc-macro1 whose build script downloaded and ran a binary during cargo build. The crate was deleted 86 minutes later after 2,285 downloads.
- arrayref 0.3.10 was published at 07:15 UTC and deleted at 08:41 UTC — 86 minutes
- It was downloaded 2,285 times, under 10% of arrayref's traffic in that window
- The attacker yanked versions 0.3.5–0.3.9 so Cargo's warning pointed to the poisoned one
- proc-macro1 is a typosquat of proc-macro2 from account dtolney, one letter off dtolnay
Read next
Security