< BACK TO NEWS
negativeSYS.SOURCE: SafeDep2026-08-20T13:23:12Z

Malicious Rust Crate Arrayref Executes Build-Time Payload via Typosquatted Dependency

A compromised Rust crate, arrayref, was found to execute a build-time payload via a typosquatted dependency on proc-macro1, which downloaded and ran a remote binary during compilation. The malicious versions were removed from crates.io after discovery.

Comments

Read original article

*** END OF TRANSMISSION ***