
Tech
Rust malware in arrayref: how a build.rs ran a payload at compile time
On August 20, 2026, Rust malware reached crates.io through one of its most-downloaded small crates. arrayref 0.3.10 added a single dependency, proc-macro1 , a look-alike of the real proc-macro2 , and that crate's build script downloaded and started a binary while your project compiled. The Rust security response team deleted it 86 minutes later . If you write Rust, the mechanism matters more than the crate: cargo build runs your dependencies' code on your machine, as you, by design.
...
Read the full discussion on Dev.to
This article was aggregated from Dev.to. Click to join the conversation.
View on Dev.to