Hostile 92% rust 257,154,926 installs Download

arrayref 0.3.10

Typosquatting proc-macro1 dependency

“Macros to take array references of slices”

Crate carries unreferenced proc-macroN digit-squatCrate declares and locks proc-macroN digit-squat
SHA-25625ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae

Also flagged by https://falhumaid.github.io/DFIR_Radar_RSS/rss.xml (North Korean Hackers Tied to Rust Supply Chain Attack), https://safedep.io/rss.xml (Malicious Rust Crate arrayref Runs a Build-Time Payload), https://www.aikido.dev/blog/rss.xml (Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack), https://www.stepsecurity.io/blog/rss.xml (Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build Time), osv (MAL-2026-14336: Malicious code in arrayref (crates.io)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.