The Rust Security Response Team detected and removed a malicious proc-macro1 crate that executed a build script downloading a harmful payload. Several widely used crates, including arrayref, internment, and append-only-vec, were compromised via republishing and dependency injection, but the malicious versions have been yanked and the account locked. Users are advised to audit their local dependencies for the listed compromised crates.
Background
Supply chain attacks targeting package registries are an increasing threat, where compromised packages can distribute malware to thousands of downstream projects. The Rust ecosystem has faced notable incidents, making timely response and developer awareness critical.
- Source
- Lobsters
- Published
- Aug 20, 2026 at 05:54 PM
- Score
- 9.0 / 10