Radar · Rust · Archive · Week 35 · Aug 24 – 30, 2026
Supply chain attack on arrayref
Breakingecosystem
- What changed
- A supply‑chain attack on the
arrayrefcrate was reported. - Production impact
- The source does not say.
- Try it
- Check the crate’s current version and its Cargo.lock entry for any unexpected changes.
- Source
- blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Understand it, then run it
A recent incident involved a malicious crate named proc-macro1. It was used by other crates, including the popular arrayref. The Rust Security Response Team removed the offending versions from crates.io. If you have used arrayref or any of the listed crates, you should check whether the malicious version was downloaded to your local cache.
The fix is not a language change; it is a security action. The Rust ecosystem now has the malicious versions deleted and the account locked. You can verify your local cache to be sure you did not pull in the bad code.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed