Arrayref v0.3.10 and v0.3.11 compromised on crates.io
By stevefan1999 · 2026-08-20 · 1 points · 0 comments
https://crates.io/crates/arrayref has a supply chain attack that runs malicious build script through a transient build-time dependency during `cargo build` with https://crates.io/crates/proc-macro-en/1.0.10/ (now deleted) Some mo…
Open the full discussion on BetterNews