This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Rust · Archive · Week 35 · Aug 24 – 30, 2026

Supply chain attack on arrayref

Breakingecosystem

What changed
A supply‑chain attack on the arrayref crate was reported.
Production impact
The source does not say.
Try it
Check the crate’s current version and its Cargo.lock entry for any unexpected changes.
Source
blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/

Understand it, then run it

A recent incident involved a malicious crate named proc-macro1. It was used by other crates, including the popular arrayref. The Rust Security Response Team removed the offending versions from crates.io. If you have used arrayref or any of the listed crates, you should check whether the malicious version was downloaded to your local cache.

The fix is not a language change; it is a security action. The Rust ecosystem now has the malicious versions deleted and the account locked. You can verify your local cache to be sure you did not pull in the bad code.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed