Rust crate arrayref poisoned with malware that ran at compile time, deleted in 86 minutes

On August 20, 2026, a malicious version of the popular Rust crate arrayref (0.3.10) was published to crates.io, carrying a typosquatted dependency called proc-macro1 whose build script downloaded and executed a binary on developers' machines during compilation. The attacker, operating from an account named dtolney — one letter off from trusted maintainer dtolnay — staged a clean decoy crate before adding the malicious build script, and also yanked legitimate arrayref versions to steer users toward the infected release. The Rust security response team deleted the malicious crate 86 minutes after publication, locking the compromised account and restoring clean versions; two other affected crates, internment and append-only-vec, were removed within two hours. According to RUSTSEC-2026-0260, the poisoned version was downloaded 2,285 times, with the maintainer's account believed to have been compromised rather than acting maliciously. The incident highlights a fundamental aspect of Rust's build system: Cargo runs dependency build scripts with full developer permissions and no sandbox, meaning a single added dependency line is sufficient to execute arbitrary code at compile time.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in