Benign rust Download

proc-macro1 1.0.107

Rustls verifier skips server hostname validationArchive ships a root-level test tree
SHA-25661198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4

Also flagged by https://falhumaid.github.io/DFIR_Radar_RSS/rss.xml (North Korean Hackers Tied to Rust Supply Chain Attack), https://safedep.io/rss.xml (Malicious Rust Crate arrayref Runs a Build-Time Payload), https://www.aikido.dev/blog/rss.xml (Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack), https://www.stepsecurity.io/blog/rss.xml (Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build Time), osv (MAL-2026-14338: Malicious code in proc_macro1 (crates.io)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.