Supply chain attack on arrayref

97 · The Rust Programming Language · Aug. 20, 2026, 12:24 p.m.
Summary
The blog post reports on a supply chain attack affecting the Rust crate ecosystem, specifically mentioning that the 'proc-macro1' crate was found to be malicious. Several associated crates were deleted, and users are advised to check their dependencies for compromised versions. The Rust Security Response Team has taken action and is attempting to contact the impacted author.