- arrayref 0.3.10 depends on proc-macro1 · build.rs downloads and runs a binary at compile time
- clean versions yanked → Cargo's own warning walks you to the poisoned one · 2,285 downloads in 86 min
+ deleted in 86 minutes · account locked · RUSTSEC-2026-0260 · git blame: Cargo's model 55 / one account 30 / the digit 1, 15A four-macro Rust crate with a quarter of a billion downloads adds one dependency, and cargo build runs a stranger's binary on your machine. August 20th, 2026. arrayref 0.3.10 lands on crates.io depending on proc-macro1. Not proc-macro2, the real one: one digit off, and its build script runs a payload while your project compiles. Rust's security team deletes it 86 minutes later. SafeDep publishes the teardown. Hacker News: 554 points.
How it happens, why Cargo lets it, and who gets the blame. Two a.m., UTC. An account called d-tolney, one letter from David Tolnay, who maintains half of Rust, publishes proc-macro1 1.0.106: real proc-macro2, renamed. Staging. 07:11. Version 1.0.107 adds a build script, plus base64, TLS and an HTTP client. For a token parser.
07:15. The maintainer's account republishes arrayref as 0.3.10 and yanks every older version. Cargo prints: consider updating to a version that is not yanked. The only one left is the poisoned one. The warning is the lure. Same minute, a security firm reports it to Rust. 07:54, a RustSec issue. 08:29, an issue on the repo; the attacker answers with 0.3.11 and a second malicious dependency. 08:41, deleted. Eighty-six minutes. Why? One: Cargo builds every declared dependency, called or not. One manifest line is enough.
Two: a build script runs on your machine, as you, with your SSH keys and cargo token, before your code compiles. No sandbox, by design: it's how crates find C libraries. Three: inside is real proc-macro2, so the build succeeds. The payload: a TLS client that trusts any certificate fetches a binary, drops it in /tmp/rust-setup and spawns it detached. On Windows it detours through wscript to escape Cargo's job object; a source comment says so.
The second stage, per the RustSec thread: a remote-access tool aimed at browsers and crypto wallets. Poetic, since arrayref's biggest users include secp256k1 and Solana. git blame. Cargo's model, fifty-five percent: dependencies run code on your machine at compile time, no sandbox, and the yank warning walked people to the poison. One account, thirty: one credential republishes a crate a quarter of a billion downloads trust. The digit one, fifteen: one keystroke from Rust's most trusted crate, and nobody reads the tree. Blast radius: 2,285 downloads in 86 minutes. Under ten percent of traffic, because most lockfiles held 0.3.9. crates.io says no evidence of usage. Two people on the RustSec thread disagree; one finds a systemd service.
On Hacker News the top thread isn't about the malware. It's the crate page, where 0.3.10 now never existed. Verdict, postmortem: needs review. Eighty-six minutes to delete, a same-day blog post, the account locked: that part is ship it. But the crate page shows nothing happened, cargo audit stays silent on a cached copy, and build scripts still run as you. Monday: run the Rust blog's find command, and treat a yank warning as a question, not an instruction. Send me the incident you're still not allowed to talk about, in the comments, or at the daily diff dot dev.
Verdict: NEEDS REVIEW — deleted in 86 min · but no trace on the page, cargo audit silent, build.rs still unsandboxed
Sources
Rust Blog, security-response: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
RUSTSEC-2026-0260: https://github.com/rustsec/advisory-db/blob/main/crates/arrayref/RUSTSEC-2026-0260.md
https://github.com/rustsec/advisory-db/pull/3162
RustSec issue #3161 (original report): https://github.com/rustsec/advisory-db/issues/3161
SafeDep analysis: https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/
https://github.com/droundy/arrayref/issues/33
https://crates.io/crates/arrayref
https://news.ycombinator.com/item?id=49374269
https://news.ycombinator.com/item?id=49372853
https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/
https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
https://blog.rust-lang.org/2026/02/13/crates.io-malicious-crate-update/
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · thedailydiff.dev · forward this to the intern who deployed on Friday.

