On August 20, 2026, Rust malware reached crates.io through one of its most-downloaded small crates. arrayref 0.3.10 added a single dependency, proc-macro1 , a look-alike of the real proc-macro2 , and that crate's build script downloaded and started a binary while your project compiled. The Rust security response team deleted it 86 minutes later . If you write Rust, the mechanism matters more than the crate: cargo build runs your dependencies' code on your machine, as you, by design. ...