rust-arrayref-2026 · Disclosed 2026-08-20
Rust: malicious build code in legitimate crate updates
The Rust team reported malicious dependencies in updates to arrayref and related crates. Build-time code retrieved a payload; malicious versions were removed.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
The Rust team reported removing malicious releases and locking the publisher account.
[s1]Response
Evidence relevant to prevention
Operational controls to inspect
Check dependency versions and build-script execution; examine exposed credentials and hosts rather than only replacing dependencies.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Downloads are not a victim count; downstream compromise scope is unknown.
Sources
[s1] Rust Project · Primary source
Supply-chain attack on arrayref ↗Published 2026-08-20 · Reviewed 2026-10-02
[s2] Rust Project · Primary source
Targeted attacks on Rust crate maintainers ↗Published 2026-09-17 · Reviewed 2026-10-02