• Supply chain attack on arrayref (Rust blog)

    From LWN.net@86:200/23 to All on Thu Aug 20 09:17:39 2026
    The Rust blog reports
    on a malicious crate, called proc-macro1, that was uploaded to the
    crates.io repository.

    Furthermore, we discovered that the popular arrayref crate
    had recently been republished and made to depend on this crate,
    with the most recent versions yanked. We have removed the malicious
    version and unyanked the maliciously-yanked versions. Other crates
    by that author (internment, append-only-vec) were
    also affected so we have done the same for those, and locked the
    account as a precaution. We do not believe the author of
    arrayref to be acting maliciously, but their computer or
    credentials are likely compromised, and we are attempting to
    contact them.

    https://lwn.net/Articles/1089720/
    --- SBBSecho 3.37-Linux
    * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (86:200/23)