Rust Supply Chain Attack Distributes Build-Time Malware via Compromised Crates.io Accounts
Malicious updates to arrayref, internment, and append-only-vec execute remote payloads during compilation; 245 million potential downloads at risk

Key Takeaways
- Malicious updates to arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 were removed from crates.io.
- A compromised maintainer account was used to distribute crates containing a typosquatted dependency with a build script that executed a remote payload during compilation.
- The Rust ecosystem and downstream projects using these crates are potentially affected, with reported download counts in the hundreds of millions.
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




