← Incident database

rust-arrayref-2026 · Disclosed 2026-08-20

Rust: malicious build code in legitimate crate updates

The Rust team reported malicious dependencies in updates to arrayref and related crates. Build-time code retrieved a payload; malicious versions were removed.

Supply chain / CICredentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Malicious arrayref, internment, and append-only-vec releases depended on proc-macro1 to retrieve a payload at build time.

    [s1]Attack overview
  • Assessment

    The August 20 report assesses compromise of a maintainer’s computer or credentials as the likely cause.

    [s1]Maintainer account

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    The Rust team reported removing malicious releases and locking the publisher account.

    [s1]Response

Evidence relevant to prevention

Operational controls to inspect

Check dependency versions and build-script execution; examine exposed credentials and hosts rather than only replacing dependencies.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Downloads are not a victim count; downstream compromise scope is unknown.

Sources

  1. [s1] Rust Project · Primary source

    Supply-chain attack on arrayref ↗

    Published 2026-08-20 · Reviewed 2026-10-02

  2. [s2] Rust Project · Primary source

    Targeted attacks on Rust crate maintainers ↗

    Published 2026-09-17 · Reviewed 2026-10-02