- Sources: RustSec advisory-db issue 3161, SafeDep analysis, HN discussion
- Summary: A malicious arrayref 0.3.10 was published to crates.io at roughly 07:15 UTC on 2026-08-20, alongside a typosquatted proc-macro1 1.0.107 at roughly 07:11 UTC, and both were still live when the RustSec issue was filed at 07:54 UTC. The build script pulled and executed an attacker binary, so compiling a project that resolved the version was enough to run it. Delivery ran through the yank warning: arrayref 0.3.5 through 0.3.9 were yanked under the compromised owner account, so cargo's advice to move off a yanked version pointed at the only remaining non-yanked release, which was the malicious one, and the reporter states this is how they were hit. SafeDep states the droundy account appears to have been compromised and that the associated GitHub repositories now return 404, and this page does not treat the maintainer as the attacker. The two sources differ on scope: the RustSec issue names arrayref 0.3.10 only, while SafeDep also lists internment 0.8.7 and append-only-vec 0.1.9 as malicious and removed, plus five further dependency crates. They also differ on downloads, roughly 152 million for the clean 0.3.9 in the advisory against about 245 million all-time for the crate in the SafeDep post, and both are usage measures rather than counts of affected builds. Whether arrayref 0.3.10 and proc-macro1 1.0.107 are still installable from crates.io was not resolved this run, so their current availability is unknown here, in contrast to internment 0.8.7 and append-only-vec 0.1.9, which SafeDep states are removed.
- Why it matters: Compiling any project that resolved arrayref 0.3.10 was enough to fetch and run an attacker binary, and the crate sits transitively under most Rust GUI work through tiny-skia, sctk-adwaita, and winit.
- Follow-up: Establish whether internment 0.8.7, append-only-vec 0.1.9, and the five further crates SafeDep names receive their own RustSec advisories, and whether the compromised account's remaining crates are audited.
send feedback on this story